pcre3: CVE-2015-3217

Related Vulnerabilities: CVE-2015-3217  

Debian Bug report logs - #787641
pcre3: CVE-2015-3217

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Wed, 3 Jun 2015 17:06:01 UTC

Severity: important

Tags: security, upstream

Found in versions pcre3/2:8.35-5, pcre3/1:8.30-5

Fixed in version pcre3/2:8.38-1

Forwarded to https://bugs.exim.org/show_bug.cgi?id=1638

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Matthew Vernon <matthew@debian.org>:
Bug#787641; Package src:pcre3. (Wed, 03 Jun 2015 17:06:05 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Matthew Vernon <matthew@debian.org>. (Wed, 03 Jun 2015 17:06:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: pcre3: CVE-2015-3217
Date: Wed, 03 Jun 2015 19:03:37 +0200
Source: pcre3
Version: 2:8.35-5
Severity: important
Tags: security upstream

Hi,

the following vulnerability was published for pcre3 (reporting this
separately instead collecting to the others since don't know affected
versions, original report confirms 8.33, 8.34, 8.35, 8.36, 8.37 to be
vulnerable).

CVE-2015-3217[0]:
PCRE Library Call Stack Overflow Vulnerability in match()

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2015-3217
[1] https://bugs.exim.org/show_bug.cgi?id=1638

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Marked as found in versions pcre3/1:8.30-5. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2015 07:06:07 GMT) (full text, mbox, link).


Set Bug forwarded-to-address to 'https://bugs.exim.org/show_bug.cgi?id=1638'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2015 07:06:08 GMT) (full text, mbox, link).


Marked as fixed in versions pcre3/2:8.38-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 23 Dec 2015 05:42:06 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 17:21:30 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.