<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>9008</bug_id>
          
          <creation_ts>2016-01-27 16:19:16 +0000</creation_ts>
          <short_desc>libpcre missing  CVE-2015-8391</short_desc>
          <delta_ts>2016-02-20 00:56:57 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>2.0.2</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>2.0.2</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Armin Kuster">akuster</reporter>
          <assigned_to name="Armin Kuster">akuster</assigned_to>
          <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>58275</commentid>
    <comment_count>0</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2016-01-27 16:19:16 +0000</bug_when>
    <thetext>CVE-2015-8391 pcre: Some pathological patterns causes pcre_compile() to run for a very long time</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>58276</commentid>
    <comment_count>1</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2016-01-27 16:28:29 +0000</bug_when>
    <thetext>I believe there is a total of 19 between jethro and fido.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>58277</commentid>
    <comment_count>2</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2016-01-27 16:31:38 +0000</bug_when>
    <thetext>I would like to update jethro to the latest libpcre 8.38.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>58278</commentid>
    <comment_count>3</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2016-01-27 16:49:16 +0000</bug_when>
    <thetext>List:
CVE-2015-3210 pcre: heap buffer overflow in pcre_compile2() / compile_regex()
CVE-2015-3217 pcre: stack overflow in match() 
CVE-2015-5073 CVE-2015-8388 pcre: Buffer overflow caused by certain patterns with an unmatched closing parenthesis

CVE-2015-8380 pcre: Heap-based buffer overflow in pcre_exec
CVE-2015-8381 pcre: Heap Overflow in compile_regex()
CVE-2015-8383 pcre: Buffer overflow caused by repeated conditional group
CVE-2015-8384 pcre: Buffer overflow caused by recursive back reference by name within certain group
CVE-2015-8385 pcre: Buffer overflow caused by forward reference by name to certain group
CVE-2015-8386 pcre: Buffer overflow caused by lookbehind assertion 
CVE-2015-8387 pcre: Integer overflow in subroutine calls
CVE-2015-8389 pcre: Infinite recursion in JIT compiler when processing certain patterns
 CVE-2015-8390 pcre: Reading from uninitialized memory when processing certain patterns 

CVE-2015-8392 pcre: Buffer overflow caused by certain patterns with duplicated named groups
CVE-2015-8393 pcre: Information leak when running pcgrep -q on crafted binary
CVE-2015-8394 pcre: Integer overflow caused by missing check for certain conditions
CVE-2015-8395 pcre: Buffer overflow caused by certain references
CVE-2016-1283 pcre: Heap buffer overflow in pcre_compile2 causes DoS</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>58757</commentid>
    <comment_count>4</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2016-02-08 23:12:25 +0000</bug_when>
    <thetext>this went is to jethro.

don&apos;t know how to handle fido. package update or a boat load of patches.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>59306</commentid>
    <comment_count>5</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2016-02-20 00:56:57 +0000</bug_when>
    <thetext>fido fixed

http://cgit.openembedded.org/openembedded-core/commit/?h=fido&amp;id=3bbd53035fb62793f1e44b24b18eb275bd860ed1</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>