Out-of-bounds read in PCRE - CVE-2017-7186

 

Out-of-bounds read in PCRE - CVE-2017-7186

Published: July 18, 2017 / Updated: October 11, 2022


Vulnerability identifier: #VU7564
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7186
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to a segmentation violation issue by the libpcre1 and libpcre2. A remote attacker can send specially crafted packets and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

PCRE
Arch Linux
Gentoo Linux
Fedora
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
Ubuntu
Dell Secure Connect Gateway
pcre (Alpine package)
libpcre3 (Ubuntu package)
mingw-glibmm24
mingw-glib2
pcre
libpcrecpp0-32bit
pcre-tools-debuginfo
pcre-tools
pcre-devel-static
libpcrecpp0-debuginfo-32bit
pcre-devel
pcre-debugsource
libpcreposix0
libpcrecpp0-debuginfo
libpcre1-32bit
libpcrecpp0
libpcre16-0-debuginfo
libpcre16-0
libpcre1-debuginfo
libpcre1
libpcreposix0-debuginfo
libpcre1-debuginfo-32bit
pcre2
selinux-policy-devel
selinux-policy
selinux-policy-minimum

How to mitigate CVE-2017-7186

Install update from vendor's website.

PCRE - update to 8.41
Dell Secure Connect Gateway - update to 5.12.00.10
pcre (Alpine package) - update to 8.40-r2
libpcre3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
mingw-glibmm24 - update to 2.56.0-1.fc28
mingw-glib2 - update to 2.56.1-1.fc28
pcre - addressed in versions 8.40-7.fc24, 8.40-7.fc25, 8.40-7.fc26
libpcrecpp0-32bit - update to 8.45-8.7.1
pcre-tools-debuginfo - update to 8.45-8.7.1
pcre-tools - update to 8.45-8.7.1
pcre-devel-static - update to 8.45-8.7.1
libpcrecpp0-debuginfo-32bit - update to 8.45-8.7.1
pcre-devel - update to 8.45-8.7.1
pcre-debugsource - update to 8.45-8.7.1
libpcreposix0 - update to 8.45-8.7.1
libpcrecpp0-debuginfo - update to 8.45-8.7.1
libpcre1-32bit - update to 8.45-8.7.1
libpcrecpp0 - update to 8.45-8.7.1
libpcre16-0-debuginfo - update to 8.45-8.7.1
libpcre16-0 - update to 8.45-8.7.1
libpcre1-debuginfo - update to 8.45-8.7.1
libpcre1 - update to 8.45-8.7.1
libpcreposix0-debuginfo - update to 8.45-8.7.1
libpcre1-debuginfo-32bit - update to 8.45-8.7.1
pcre2 - addressed in versions 10.21-18.el6, 10.21-18.el7, 10.21-18.fc24, 10.23-6.fc25, 10.23-6.fc26
selinux-policy-devel - update to 20140730-36.5.2
selinux-policy - update to 20140730-36.5.2
selinux-policy-minimum - update to 20140730-36.5.2

External References

Related Security Bulletins