Buffer overflow - CVE-2017-7245
Published: July 18, 2017 / Updated: July 18, 2017
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error in pcre32_copy_substring() function in pcre_get.c in libpcre1 in PCRE 8.40. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Arch Linux
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
Fedora
Dell Secure Connect Gateway
pcre (Alpine package)
mingw-glibmm24
mingw-glib2
libpcreposix0
pcre-tools-debuginfo
pcre-tools
pcre-devel-static
libpcrecpp0-debuginfo-32bit
libpcrecpp0-32bit
pcre-devel
pcre-debugsource
libpcreposix0-debuginfo
libpcrecpp0-debuginfo
libpcrecpp0
libpcre16-0-debuginfo
libpcre16-0
libpcre1-debuginfo
libpcre1-debuginfo-32bit
libpcre1
libpcre1-32bit
selinux-policy-devel
selinux-policy
selinux-policy-minimum
How to mitigate CVE-2017-7245
pcre (Alpine package) - update to 8.41-r0
mingw-glibmm24 - update to 2.56.0-1.fc28
mingw-glib2 - update to 2.56.1-1.fc28
libpcreposix0 - update to 8.45-8.7.1
pcre-tools-debuginfo - update to 8.45-8.7.1
pcre-tools - update to 8.45-8.7.1
pcre-devel-static - update to 8.45-8.7.1
libpcrecpp0-debuginfo-32bit - update to 8.45-8.7.1
libpcrecpp0-32bit - update to 8.45-8.7.1
pcre-devel - update to 8.45-8.7.1
pcre-debugsource - update to 8.45-8.7.1
libpcreposix0-debuginfo - update to 8.45-8.7.1
libpcrecpp0-debuginfo - update to 8.45-8.7.1
libpcrecpp0 - update to 8.45-8.7.1
libpcre16-0-debuginfo - update to 8.45-8.7.1
libpcre16-0 - update to 8.45-8.7.1
libpcre1-debuginfo - update to 8.45-8.7.1
libpcre1-debuginfo-32bit - update to 8.45-8.7.1
libpcre1 - update to 8.45-8.7.1
libpcre1-32bit - update to 8.45-8.7.1
selinux-policy-devel - update to 20140730-36.5.2
selinux-policy - update to 20140730-36.5.2
selinux-policy-minimum - update to 20140730-36.5.2