You are here
Home > Preporuke > Ranjivost programskog paketa pcre

Ranjivost programskog paketa pcre

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2015-11-26 19:19:58.808625

Name : pcre
Product : Fedora 23
Version : 8.38
Release : 1.fc23
Summary : Perl-compatible regular expression library
Description :
Perl-compatible regular expression library.
PCRE has its own native API, but a set of “wrapper” functions that are based on
the POSIX API are also supplied in the library libpcreposix. Note that this
just provides a POSIX calling interface to PCRE: the regular expressions
themselves still follow Perl syntax and semantics. The header file
for the POSIX-style functions is called pcreposix.h.

Update Information:

This release fixes various bugs when compiling or matching expressions. It also
fixes how pcregrep handles binary files. It also fixes a heap-based buffer
overflow in pcre_exec() when ovector has size 1 (bug #1285415)

[ 1 ] Bug #1285413 – pcre: Heap-based buffer overflow in pcre_exec

This update can be installed with the “yum” update program. Use
su -c ‘yum update pcre’ at the command line.
For more information, refer to “Managing Software with yum”,
available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list



Fedora Update Notification
2015-12-11 21:20:33.553677

Name        : pcre
Product     : Fedora 22
Version     : 8.37
Release     : 7.fc22
URL         :
Summary     : Perl-compatible regular expression library
Description :
Perl-compatible regular expression library.
PCRE has its own native API, but a set of “wrapper” functions that are based on
the POSIX API are also supplied in the library libpcreposix. Note that this
just provides a POSIX calling interface to PCRE: the regular expressions
themselves still follow Perl syntax and semantics. The header file
for the POSIX-style functions is called pcreposix.h.

Update Information:

This release fixes CVE-2015-8380 (a heap-based buffer overflow in pcre_exec()
when ovector has size 1).  —-  This release fixes a crash when compiling an
expression with long (*MARK) or (*THEN) names. It also fixes compiling a POSIX
character class followed by a single ASCII character in a class item while UCP
mode is active. It also fixes mismatching characters in the range 128-255
against [:punct:] in UCP mode.

  [ 1 ] Bug #1285413 – CVE-2015-8380 pcre: Heap-based buffer overflow in pcre_exec

This update can be installed with the “yum” update program. Use
su -c ‘yum update pcre’ at the command line.
For more information, refer to “Managing Software with yum”,
available at

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list


AutorTomislav Protega
Cert idNCERT-REF-2015-11-0027-ADV
ID izvornikaFEDORA-2015-994
More in Preporuke
Ranjivost programskog paketa dpkg

Otkrivena je ranjivost prekoračenja spremnika stoga u dpkg-deb komponenti programskog paketa dpkg uzrokovana neispravnim upravljanjem posebno oblikovanim Debian binarnim paketima...
