SB2017100809 - Gentoo update for PCRE2
Published: October 8, 2017 Updated: October 11, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2017-7186)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to a segmentation violation issue by the libpcre1 and libpcre2. A remote attacker can send specially crafted packets and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
2) Buffer overflow (CVE-ID: CVE-2017-8399)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
3) Heap-based buffer overflow (CVE-ID: CVE-2017-8786)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in pcre2test.c in PCRE2 10.23. A remote attacker can use a crafted regular expression. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.