Bug 9008 - libpcre missing CVE-2015-8391
Summary: libpcre missing CVE-2015-8391
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: 2.0.2
Hardware: x86 Multiple
: Medium+ normal
Target Milestone: 2.0.2
Assignee: Armin Kuster
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2016-01-27 16:19 UTC by Armin Kuster
Modified: 2016-02-20 00:56 UTC (History)
2 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Don't know


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Armin Kuster 2016-01-27 16:19:16 UTC
CVE-2015-8391 pcre: Some pathological patterns causes pcre_compile() to run for a very long time
Comment 1 Armin Kuster 2016-01-27 16:28:29 UTC
I believe there is a total of 19 between jethro and fido.
Comment 2 Armin Kuster 2016-01-27 16:31:38 UTC
I would like to update jethro to the latest libpcre 8.38.
Comment 3 Armin Kuster 2016-01-27 16:49:16 UTC
List:
CVE-2015-3210 pcre: heap buffer overflow in pcre_compile2() / compile_regex()
CVE-2015-3217 pcre: stack overflow in match() 
CVE-2015-5073 CVE-2015-8388 pcre: Buffer overflow caused by certain patterns with an unmatched closing parenthesis

CVE-2015-8380 pcre: Heap-based buffer overflow in pcre_exec
CVE-2015-8381 pcre: Heap Overflow in compile_regex()
CVE-2015-8383 pcre: Buffer overflow caused by repeated conditional group
CVE-2015-8384 pcre: Buffer overflow caused by recursive back reference by name within certain group
CVE-2015-8385 pcre: Buffer overflow caused by forward reference by name to certain group
CVE-2015-8386 pcre: Buffer overflow caused by lookbehind assertion 
CVE-2015-8387 pcre: Integer overflow in subroutine calls
CVE-2015-8389 pcre: Infinite recursion in JIT compiler when processing certain patterns
 CVE-2015-8390 pcre: Reading from uninitialized memory when processing certain patterns 

CVE-2015-8392 pcre: Buffer overflow caused by certain patterns with duplicated named groups
CVE-2015-8393 pcre: Information leak when running pcgrep -q on crafted binary
CVE-2015-8394 pcre: Integer overflow caused by missing check for certain conditions
CVE-2015-8395 pcre: Buffer overflow caused by certain references
CVE-2016-1283 pcre: Heap buffer overflow in pcre_compile2 causes DoS
Comment 4 Armin Kuster 2016-02-08 23:12:25 UTC
this went is to jethro.

don't know how to handle fido. package update or a boat load of patches.