Lucene search

K
centosCentOS ProjectCESA-2007:1052
HistoryNov 10, 2007 - 5:09 a.m.

pcre security update

2007-11-1005:09:58
CentOS Project
lists.centos.org
50

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.021

Percentile

89.2%

CentOS Errata and Security Advisory CESA-2007:1052

PCRE is a Perl-compatible regular expression library.

Flaws were found in the way PCRE handles certain malformed regular
expressions. If an application linked against PCRE, such as Konqueror,
parses a malicious regular expression, it may be possible to run arbitrary
code as the user running the application. (CVE-2005-4872, CVE-2006-7227)

Users of PCRE are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2007-November/076571.html
https://lists.centos.org/pipermail/centos-announce/2007-November/076572.html
https://lists.centos.org/pipermail/centos-announce/2007-November/076575.html
https://lists.centos.org/pipermail/centos-announce/2007-November/076576.html

Affected packages:
pcre
pcre-devel

Upstream details at:
https://access.redhat.com/errata/RHSA-2007:1052

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.021

Percentile

89.2%