OpenPKG Security Advisory
OpenPKG-SA-2005.018
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2005.018
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2005.018
Advisory Published: 2008-08-07 22:03 UTC
Issue Id (internal): OpenPKG-SI-20050905.01
Issue First Created: 2005-09-05
Issue Last Modified: 2006-11-28
Issue Revision: 06
Subject Name: pcre
Subject Summary: Perl Compatible Regular Expressions
Subject Home: http://www.pcre.org/
Subject Versions: * <= 6.1
Vulnerability Id: CVE-2005-2491
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector: local system
Attack Impact: arbitrary code execution
Description:
An integer overflow problem was discovered in the Perl Compatible
Regular Expressions (PCRE) [1] library, version 6.2 and earlier.
The problem allows a remote or local attacker to execute arbitrary
code by causing a heap-based buffer overflow via quantifier values
in regular expressions. As PCRE is a popular library, this problem
affects many applications.
References:
[1] http://www.pcre.org/
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491
[3] http://www.openpkg.org/tutorial.html#regular-source
[4] http://www.openpkg.org/tutorial.html#regular-binary
[5] ftp://ftp.openpkg.org/release/2.4/UPD/pcre-6.0-2.4.1.src.rpm
[6] ftp://ftp.openpkg.org/release/2.3/UPD/pcre-5.0-2.3.1.src.rpm
[7] ftp://ftp.openpkg.org/release/2.4/UPD/
[8] ftp://ftp.openpkg.org/release/2.3/UPD/
[9] http://www.openpkg.org/security.html#signature
Primary Package Name: pcre
Primary Package Home: http://openpkg.org/go/package/pcre
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Community 2.3-SOLID exim-4.50-2.3.0
OpenPKG Community 2.3-SOLID fsl-1.6.0-2.3.2
OpenPKG Community 2.3-SOLID hypermail-2.1.8-2.3.0
OpenPKG Community 2.3-SOLID l2-0.9.10-2.3.1
OpenPKG Community 2.3-SOLID lmtp2nntp-1.3.0-2.3.1
OpenPKG Community 2.3-SOLID pcre-5.0-2.3.0
OpenPKG Community 2.3-SOLID str-0.9.10-2.3.1
OpenPKG Community 2.3-SOLID tin-1.6.2-2.3.0
OpenPKG Community 2.3-SOLID wml-2.0.9-2.3.1
OpenPKG Community 2.4-SOLID exim-4.51-2.4.0
OpenPKG Community 2.4-SOLID fsl-1.6.0-2.4.0
OpenPKG Community 2.4-SOLID hypermail-2.1.8-2.4.0
OpenPKG Community 2.4-SOLID l2-0.9.10-2.4.0
OpenPKG Community 2.4-SOLID lmtp2nntp-1.3.0-2.4.0
OpenPKG Community 2.4-SOLID pcre-6.0-2.4.0
OpenPKG Community 2.4-SOLID str-0.9.10-2.4.0
OpenPKG Community 2.4-SOLID tin-1.6.2-2.4.0
OpenPKG Community 2.4-SOLID wml-2.0.9-2.4.0
OpenPKG Community CURRENT exim-4.52-20050701
OpenPKG Community CURRENT fsl-1.6.0-20050808
OpenPKG Community CURRENT hypermail-2.1.8-20050324
OpenPKG Community CURRENT l2-0.9.10-20050615
OpenPKG Community CURRENT lmtp2nntp-1.3.0-20050615
OpenPKG Community CURRENT pcre-6.1-20050622
OpenPKG Community CURRENT str-0.9.10-20050615
OpenPKG Community CURRENT tin-1.6.2-20040207
OpenPKG Community CURRENT wml-2.0.9-20050617
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Community 2.3-SOLID exim-4.50-2.3.1
OpenPKG Community 2.3-SOLID fsl-1.6.0-2.3.3
OpenPKG Community 2.3-SOLID hypermail-2.1.8-2.3.1
OpenPKG Community 2.3-SOLID l2-0.9.10-2.3.2
OpenPKG Community 2.3-SOLID lmtp2nntp-1.3.0-2.3.2
OpenPKG Community 2.3-SOLID pcre-5.0-2.3.1
OpenPKG Community 2.3-SOLID str-0.9.10-2.3.2
OpenPKG Community 2.3-SOLID tin-1.6.2-2.3.1
OpenPKG Community 2.3-SOLID wml-2.0.9-2.3.2
OpenPKG Community 2.4-SOLID exim-4.51-2.4.1
OpenPKG Community 2.4-SOLID fsl-1.6.0-2.4.1
OpenPKG Community 2.4-SOLID hypermail-2.1.8-2.4.1
OpenPKG Community 2.4-SOLID l2-0.9.10-2.4.1
OpenPKG Community 2.4-SOLID lmtp2nntp-1.3.0-2.4.1
OpenPKG Community 2.4-SOLID pcre-6.0-2.4.1
OpenPKG Community 2.4-SOLID str-0.9.10-2.4.1
OpenPKG Community 2.4-SOLID tin-1.6.2-2.4.1
OpenPKG Community 2.4-SOLID wml-2.0.9-2.4.1
OpenPKG Community CURRENT exim-4.52-20050905
OpenPKG Community CURRENT fsl-1.6.0-20050905
OpenPKG Community CURRENT hypermail-2.1.8-20050905
OpenPKG Community CURRENT l2-0.9.10-20050905
OpenPKG Community CURRENT lmtp2nntp-1.3.0-20050905
OpenPKG Community CURRENT pcre-6.2-20050802
OpenPKG Community CURRENT str-0.9.10-20050905
OpenPKG Community CURRENT tin-1.6.2-20050905
OpenPKG Community CURRENT wml-2.0.9-20050905