MGASA-2015-0267
Dashboard / Vulnerabilities / MGASA-2015-0267
Summary: Updated pcre package fixes security vulnerability
Details: PCRE library is prone to a vulnerability which leads to Heap Overflow. During subpattern calculation of a malformed regular expression, an offset that is used as an array index is fully controlled and can be large enough so that unexpected heap memory regions are accessed (CVE-2015-5073).
References: https://advisories.mageia.org/MGASA-2015-0267.html, https://bugs.mageia.org/show_bug.cgi?id=16217, http://openwall.com/lists/oss-security/2015/06/26/3
Affected packages
Package
Name: pcre
Purl: pkg:rpm/mageia/pcre?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -8.37-2.1.mga5
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
