oss-sec mailing list archives
CVE request: Heap buffer overflow in pcretest
From: Adam Maris <amaris () redhat com>
Date: Mon, 29 Feb 2016 10:15:39 +0100
Heap-based buffer overread caused by specially crafted input triggering infinite loop in pcretest.c was found affecting pcre 8.38. pcretest went into loop if global matching was requested with an ovector size less than 2. Upstream bug: https://bugs.exim.org/show_bug.cgi?id=1777 Upstream fix: http://vcs.pcre.org/pcre?view=revision&revision=1637 Regards, -- Adam Mariš, Red Hat Product Security 1CCD 3446 0529 81E3 86AF 2D4C 4869 76E7 BEF0 6BC2
Current thread:
- CVE request: Heap buffer overflow in pcretest Adam Maris (Feb 29)
- Re: CVE request: Heap buffer overflow in pcretest cve-assign (Feb 29)