Get a Pentest and security assessment of your IT network.

Advisories

Gentoo Linux Security Advisory 200711-30

Gentoo Linux Security Advisory GLSA 200711-30 – Tavis Ormandy (Google Security) discovered multiple vulnerabilities in PCRE. He reported an error when processing QE sequences with unmatched E codes that can lead to the compiled bytecode being corrupted. PCRE does not properly calculate sizes for unspecified multiple forms of character class, which triggers a buffer overflow. Further improper calculations of memory boundaries were reported when matching certain input bytes against regex patterns in non UTF-8 mode and when searching for unmatched brackets or parentheses. Multiple integer overflows when processing escape sequences may lead to invalid memory read operations or potentially cause heap-based buffer overflows. PCRE does not properly handle P and P{x} sequences which can lead to heap-based buffer overflows or trigger the execution of infinite loops, PCRE is also prone to an error when optimizing character classes containing a singleton UTF-8 sequence which might lead to a heap-based buffer overflow. Versions less than 7.3-r1 are affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61164/glsa-200711-30.txt

Source: https://packetstormsecurity.com/files/61164/Gentoo-Linux-Security-Advisory-200711-30.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534