PROBLEM: | It was discovered that PCRE, the Perl-Compatible Regular Expression library, may encounter a heap overflow condition when compiling certain regular expressions involving in-pattern options and branches, potentially leading to arbitrary code execution. |
PLATFORM: | Debian GNU/Linux 4.0 (etch) |
DAMAGE: | Arbitrary code execution. |
SOLUTION: | Upgrade to the appropriate version. |
VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. May encounter a heap overflow condition when compiling certain regular expressions involving in-pattern options and branches, potentially leading the arbitrary code execution. |
CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
7.5 5.9 (AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C) |
LINKS: | |
CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-336.shtml |
ORIGINAL BULLETIN: | http://www.debian.org/security/2008/dsa-1602 |
CVE: | CVE-2008-2371 |
[***** Start Debian Security Advisory DSA-1602-1 *****]
Tavis Ormandy discovered that PCRE, the Perl-Compatible Regular Expression library, may encounter a heap overflow condition when compiling certain regular expressions involving in-pattern options and branches, potentially leading to arbitrary code execution.
For the stable distribution (etch), this problem has been fixed in version 6.7+7.4-4.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your pcre3 packages.
MD5 checksums of the listed files are available in the original advisory.
[***** End Debian Security Advisory DSA-1602-1 *****]
Voice: +1 925-422-8193 (7 x 24) FAX: +1 925-423-8002 STU-III: +1 925-423-2604 E-mail: ciac@ciac.org World Wide Web: http://www.ciac.org/ Anonymous FTP: ftp.ciac.org