SUSE-SU-2021:3652-1
Dashboard / Vulnerabilities / SUSE-SU-2021:3652-1
SUSE-SU-2021:3652-1
Summary: Security update for pcre
Details: This update for pcre fixes the following issues: Update pcre to version 8.45: - CVE-2020-14155: Fixed integer overflow via a large number after a '(?C' substring (bsc#1172974). - CVE-2019-20838: Fixed buffer over-read in JIT compiler (bsc#1172973). - CVE-2017-7244: Fixed invalid read in _pcre32_xclass() (bsc#1030807). - CVE-2017-7245: Fixed buffer overflow in the pcre32_copy_substring (bsc#1030805). - CVE-2017-7246: Fixed another buffer overflow in the pcre32_copy_substring (bsc#1030803). - CVE-2017-7186: Fixed denial of service caused by an invalid Unicode property lookup (bsc#1030066). - CVE-2017-6004: Fixed denial of service via crafted regular expression (bsc#1025709).
References: https://www.suse.com/support/update/announcement/2021/suse-su-20213652-1/, https://bugzilla.suse.com/1025709, https://bugzilla.suse.com/1030066, https://bugzilla.suse.com/1030803, https://bugzilla.suse.com/1030805, https://bugzilla.suse.com/1030807, https://bugzilla.suse.com/1172973, https://bugzilla.suse.com/1172974, https://www.suse.com/security/cve/CVE-2017-6004, https://www.suse.com/security/cve/CVE-2017-7186, https://www.suse.com/security/cve/CVE-2017-7244, https://www.suse.com/security/cve/CVE-2017-7245, https://www.suse.com/security/cve/CVE-2017-7246, https://www.suse.com/security/cve/CVE-2019-20838, https://www.suse.com/security/cve/CVE-2020-14155
Affected packages
Package
Name: pcre
Purl: pkg:rpm/suse/pcre&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
