Bug#778397: Henry Spencer regular expressions (regex) library contains a heap overflow vulnerability

2015-02-14 Thread Andreas Tille
Hi Luciano, I can confirm that the problem affects testing and unstable. The package is not in stable. I have commited a patch in SVN: https://anonscm.debian.org/viewvc/debian-med/trunk/packages/rcsb-core-wrapper/trunk/debian/patches/regcomp_cert_fix.patch?view=markup Upstream is in CC of t

Bug#778397: Henry Spencer regular expressions (regex) library contains a heap overflow vulnerability

2015-02-14 Thread Luciano Bello
Package: librcsb-core-wrapper Severity: important Tags: security patch The security team received a report from the CERT Coordination Center that the Henry Spencer regular expressions (regex) library contains a heap overflow vulnerability. It looks like this package includes the affected code at