CVE-2022-1586 CVE-2022-1587

Related Vulnerabilities: CVE-2022-1586   CVE-2022-1587  

Debian Bug report logs - #1011954
CVE-2022-1586 CVE-2022-1587

version graph

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Fri, 27 May 2022 17:27:01 UTC

Severity: important

Tags: security

Found in version pcre2/10.36-2

Fixed in version pcre2/10.40-1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Matthew Vernon <matthew@debian.org>:
Bug#1011954; Package src:pcre2. (Fri, 27 May 2022 17:27:03 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Matthew Vernon <matthew@debian.org>. (Fri, 27 May 2022 17:27:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2022-1586 CVE-2022-1587
Date: Fri, 27 May 2022 19:24:12 +0200
Source: pcre2
Version: 10.36-2
Severity: important
Tags: security
X-Debbugs-Cc: Debian Security Team <team@security.debian.org>

CVE-2022-1587
https://github.com/PCRE2Project/pcre2/commit/03654e751e7f0700693526b67dfcadda6b42c9d0

CVE-2022-1586
https://github.com/PCRE2Project/pcre2/commit/50a51cb7e67268e6ad417eb07c9de9bfea5cc55a
https://github.com/PCRE2Project/pcre2/commit/d4fa336fbcc388f89095b184ba6d99422cfc676c

Cheers,
        Moritz
					



Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#1011954; Package src:pcre2. (Fri, 27 May 2022 17:57:03 GMT) (full text, mbox, link).


Acknowledgement sent to Matthew Vernon <matthew@debian.org>:
Extra info received and forwarded to list. (Fri, 27 May 2022 17:57:03 GMT) (full text, mbox, link).


Message #10 received at 1011954@bugs.debian.org (full text, mbox, reply):

From: Matthew Vernon <matthew@debian.org>
To: Moritz Muehlenhoff <jmm@debian.org>, 1011954@bugs.debian.org
Subject: Re: Bug#1011954: CVE-2022-1586 CVE-2022-1587
Date: Fri, 27 May 2022 18:52:11 +0100
Hi,

Would you like me to prepare an upload for these, or are you working on 
this?

[sorry, it's not clear from the bug report]

Thanks,

Matthew



Marked as fixed in versions pcre2/10.40-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Fri, 27 May 2022 18:45:03 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sat May 28 13:12:53 2022; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.