Bug 9008

Summary: libpcre missing CVE-2015-8391
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Armin Kuster <akuster>
Component: coreAssignee: Armin Kuster <akuster>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: meta.mr.watcher, meta.watcher
Version: 2.0.2   
Target Milestone: 2.0.2   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description Armin Kuster 2016-01-27 16:19:16 UTC
CVE-2015-8391 pcre: Some pathological patterns causes pcre_compile() to run for a very long time
Comment 1 Armin Kuster 2016-01-27 16:28:29 UTC
I believe there is a total of 19 between jethro and fido.
Comment 2 Armin Kuster 2016-01-27 16:31:38 UTC
I would like to update jethro to the latest libpcre 8.38.
Comment 3 Armin Kuster 2016-01-27 16:49:16 UTC
List:
CVE-2015-3210 pcre: heap buffer overflow in pcre_compile2() / compile_regex()
CVE-2015-3217 pcre: stack overflow in match() 
CVE-2015-5073 CVE-2015-8388 pcre: Buffer overflow caused by certain patterns with an unmatched closing parenthesis

CVE-2015-8380 pcre: Heap-based buffer overflow in pcre_exec
CVE-2015-8381 pcre: Heap Overflow in compile_regex()
CVE-2015-8383 pcre: Buffer overflow caused by repeated conditional group
CVE-2015-8384 pcre: Buffer overflow caused by recursive back reference by name within certain group
CVE-2015-8385 pcre: Buffer overflow caused by forward reference by name to certain group
CVE-2015-8386 pcre: Buffer overflow caused by lookbehind assertion 
CVE-2015-8387 pcre: Integer overflow in subroutine calls
CVE-2015-8389 pcre: Infinite recursion in JIT compiler when processing certain patterns
 CVE-2015-8390 pcre: Reading from uninitialized memory when processing certain patterns 

CVE-2015-8392 pcre: Buffer overflow caused by certain patterns with duplicated named groups
CVE-2015-8393 pcre: Information leak when running pcgrep -q on crafted binary
CVE-2015-8394 pcre: Integer overflow caused by missing check for certain conditions
CVE-2015-8395 pcre: Buffer overflow caused by certain references
CVE-2016-1283 pcre: Heap buffer overflow in pcre_compile2 causes DoS
Comment 4 Armin Kuster 2016-02-08 23:12:25 UTC
this went is to jethro.

don't know how to handle fido. package update or a boat load of patches.