Bug#778410: Henry Spencer regular expressions (regex) library contains a heap overflow vulnerability

2015-02-17 Thread Luciano Bello
On Sunday 15 February 2015 19.57.22 Ralf Treinen wrote: > I have to admit that my C is a bit rusty, so I cannot verify myself that > the C pointer gymnastics in the patch is correct. Please do (Luciano, > or someone else from the security team) send me a *signed* email to confirm > that the patch

Bug#778410: Henry Spencer regular expressions (regex) library contains a heap overflow vulnerability

2015-02-15 Thread Ralf Treinen
Hi, On Sat, Feb 14, 2015 at 03:35:42PM +0100, Luciano Bello wrote: > Package: yap > Severity: important > Tags: security patch > > The security team received a report from the CERT Coordination Center that > the > Henry Spencer regular expressions (regex) library contains a heap overflow > vul

Bug#778410: Henry Spencer regular expressions (regex) library contains a heap overflow vulnerability

2015-02-14 Thread Luciano Bello
Package: yap Severity: important Tags: security patch The security team received a report from the CERT Coordination Center that the Henry Spencer regular expressions (regex) library contains a heap overflow vulnerability. It looks like this package includes the affected code at that's the reas