PT-2005-5573 · Pcre · Libpcre3-Dev+9

Publicado

1970-01-01

·

Atualizado

2018-10-15

·

CVE-2007-4767

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpcrecpp0 versions (affected versions not specified) libpcre3 versions (affected versions not specified) libpcre versions prior to 7.3-r1 pcre-32bit versions (affected versions not specified) pcregrep versions (affected versions not specified) pcre versions (affected versions not specified) libpcre3-dev versions (affected versions not specified) pgrep versions (affected versions not specified) pcre-devel versions (affected versions not specified) Perl-Compatible Regular Expression (PCRE) library versions prior to 7.3
Description The issue concerns multiple vulnerabilities in the PCRE library, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially causing a denial of service or allowing the execution of arbitrary code. The vulnerabilities are related to the improper computation of the length of certain sequences, including p, P, and P{x} sequences.
Recommendations For libpcrecpp0, update to a version that addresses the vulnerabilities. For libpcre3, update to a version that addresses the vulnerabilities. For libpcre, update to version 7.3-r1 or later. For pcre-32bit, update to a version that addresses the vulnerabilities. For pcregrep, update to a version that addresses the vulnerabilities. For pcre, update to a version that addresses the vulnerabilities. For libpcre3-dev, update to a version that addresses the vulnerabilities. For pgrep, update to a version that addresses the vulnerabilities. For pcre-devel, update to a version that addresses the vulnerabilities. For Perl-Compatible Regular Expression (PCRE) library, update to version 7.3 or later.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02588
BDU:2015-02589
BDU:2015-02590
BDU:2015-02591
BDU:2015-03061
BDU:2015-04723
BDU:2015-04724
BDU:2015-04725
BDU:2015-09569
CVE-2007-4767
DSA-1399-1
DSA-1570-1
DTSA-77-1

Produtos afetados

Pcre Library
Libpcre
Libpcre3
Libpcre3-Dev
Libpcrecpp0
Pcre
Pcre-32Bit
Pcre-Devel
Pcregrep
Pgrep