Out-of-bounds read in PCRE - CVE-2017-7244

 

Out-of-bounds read in PCRE - CVE-2017-7244

Published: July 18, 2017 / Updated: August 23, 2017


Vulnerability identifier: #VU7565
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7244
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to invalid memory read flaw in the _pcre32_xclass function in pcre_xclass.c. A remote attacker can trick the victim into loading a specially crafted file and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

PCRE
Gentoo Linux
Arch Linux
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
Fedora
Dell Secure Connect Gateway
pcre (Alpine package)
mingw-glibmm24
mingw-glib2
libpcreposix0
pcre-tools-debuginfo
pcre-tools
pcre-devel-static
libpcrecpp0-debuginfo-32bit
libpcrecpp0-32bit
pcre-devel
pcre-debugsource
libpcreposix0-debuginfo
libpcrecpp0-debuginfo
libpcrecpp0
libpcre16-0-debuginfo
libpcre16-0
libpcre1-debuginfo
libpcre1-debuginfo-32bit
libpcre1
libpcre1-32bit
selinux-policy-devel
selinux-policy
selinux-policy-minimum

How to mitigate CVE-2017-7244

Update to version 8.41 (not released at the moment)

Dell Secure Connect Gateway - update to 5.12.00.10
pcre (Alpine package) - update to 8.41-r0
mingw-glibmm24 - update to 2.56.0-1.fc28
mingw-glib2 - update to 2.56.1-1.fc28
libpcreposix0 - update to 8.45-8.7.1
pcre-tools-debuginfo - update to 8.45-8.7.1
pcre-tools - update to 8.45-8.7.1
pcre-devel-static - update to 8.45-8.7.1
libpcrecpp0-debuginfo-32bit - update to 8.45-8.7.1
libpcrecpp0-32bit - update to 8.45-8.7.1
pcre-devel - update to 8.45-8.7.1
pcre-debugsource - update to 8.45-8.7.1
libpcreposix0-debuginfo - update to 8.45-8.7.1
libpcrecpp0-debuginfo - update to 8.45-8.7.1
libpcrecpp0 - update to 8.45-8.7.1
libpcre16-0-debuginfo - update to 8.45-8.7.1
libpcre16-0 - update to 8.45-8.7.1
libpcre1-debuginfo - update to 8.45-8.7.1
libpcre1-debuginfo-32bit - update to 8.45-8.7.1
libpcre1 - update to 8.45-8.7.1
libpcre1-32bit - update to 8.45-8.7.1
selinux-policy-devel - update to 20140730-36.5.2
selinux-policy - update to 20140730-36.5.2
selinux-policy-minimum - update to 20140730-36.5.2

External References

Related Security Bulletins