OESA-2023-1482
Dashboard / Vulnerabilities / OESA-2023-1482
Summary: pcre2 security update
Details: PCRE2 is a re-working of the original PCRE1 library to provide an entirely new API. Security Fix(es): Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.(CVE-2022-41409)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1482, https://nvd.nist.gov/vuln/detail/CVE-2022-41409
Affected packages
Package
Name: pcre2
Purl: pkg:rpm/openEuler/pcre2&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -10.35-5.oe1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
