Out-of-bounds read in PCRE - CVE-2017-6004
Published: October 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the compile_bracket_matchingpath() function in pcre_jit_compile.c. A remote attacker can pass a specially crafted regular expression to the application, trigger an out-of-bounds read and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
Ubuntu
Fedora
libpcre3 (Ubuntu package)
dev-libs/libpcre
pcre
libpcrecpp0-debuginfo
pcre-tools-debuginfo
pcre-tools
pcre-devel-static
libpcrecpp0-debuginfo-32bit
libpcrecpp0-32bit
pcre-devel
pcre-debugsource
libpcreposix0-debuginfo
libpcreposix0
libpcrecpp0
libpcre16-0-debuginfo
libpcre16-0
libpcre1-debuginfo
libpcre1-debuginfo-32bit
libpcre1
libpcre1-32bit
selinux-policy-minimum
selinux-policy-devel
selinux-policy
How to mitigate CVE-2017-6004
libpcre3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
dev-libs/libpcre - update to 8.40-r1
pcre - update to 8.40-2.fc24
libpcrecpp0-debuginfo - update to 8.45-8.7.1
pcre-tools-debuginfo - update to 8.45-8.7.1
pcre-tools - update to 8.45-8.7.1
pcre-devel-static - update to 8.45-8.7.1
libpcrecpp0-debuginfo-32bit - update to 8.45-8.7.1
libpcrecpp0-32bit - update to 8.45-8.7.1
pcre-devel - update to 8.45-8.7.1
pcre-debugsource - update to 8.45-8.7.1
libpcreposix0-debuginfo - update to 8.45-8.7.1
libpcreposix0 - update to 8.45-8.7.1
libpcrecpp0 - update to 8.45-8.7.1
libpcre16-0-debuginfo - update to 8.45-8.7.1
libpcre16-0 - update to 8.45-8.7.1
libpcre1-debuginfo - update to 8.45-8.7.1
libpcre1-debuginfo-32bit - update to 8.45-8.7.1
libpcre1 - update to 8.45-8.7.1
libpcre1-32bit - update to 8.45-8.7.1
selinux-policy-minimum - update to 20140730-36.5.2
selinux-policy-devel - update to 20140730-36.5.2
selinux-policy - update to 20140730-36.5.2