Bug#781795: pcre3: CVE-2015-2325: heap buffer overflow in compile_branch()

2015-06-02 Thread Zdeněk Bělehrádek
Is there any progress on this bug? We have been hit by this in production (or at least by bug with similar symptoms). For now we are using old version of libpcre, but we would like to use current version. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of

Bug#781795: pcre3: CVE-2015-2325: heap buffer overflow in compile_branch()

2015-04-25 Thread Salvatore Bonaccorso
Hi Matthew, On Thu, Apr 23, 2015 at 06:44:05PM +0100, Matthew Vernon wrote: > On 23/04/15 18:30, Salvatore Bonaccorso wrote: > > Hi Matthew, > > > > On Thu, Apr 23, 2015 at 06:21:27PM +0100, Matthew Vernon wrote: > >> Hi, > >> > >> On 03/04/15 10:30, Salvatore Bonaccorso wrote: > >> > >>> the fol

Bug#781795: pcre3: CVE-2015-2325: heap buffer overflow in compile_branch()

2015-04-23 Thread Matthew Vernon
On 23/04/15 18:30, Salvatore Bonaccorso wrote: > Hi Matthew, > > On Thu, Apr 23, 2015 at 06:21:27PM +0100, Matthew Vernon wrote: >> Hi, >> >> On 03/04/15 10:30, Salvatore Bonaccorso wrote: >> >>> the following vulnerability was published for pcre3. >>> >>> CVE-2015-2325[0]: >>> heap buffer overflo

Bug#781795: pcre3: CVE-2015-2325: heap buffer overflow in compile_branch()

2015-04-23 Thread Salvatore Bonaccorso
Hi Matthew, On Thu, Apr 23, 2015 at 06:21:27PM +0100, Matthew Vernon wrote: > Hi, > > On 03/04/15 10:30, Salvatore Bonaccorso wrote: > > > the following vulnerability was published for pcre3. > > > > CVE-2015-2325[0]: > > heap buffer overflow in compile_branch() > > Thanks for the bug report.

Bug#781795: pcre3: CVE-2015-2325: heap buffer overflow in compile_branch()

2015-04-23 Thread Matthew Vernon
Hi, On 03/04/15 10:30, Salvatore Bonaccorso wrote: > the following vulnerability was published for pcre3. > > CVE-2015-2325[0]: > heap buffer overflow in compile_branch() Thanks for the bug report. > I was not able to reproduce the actual overflow with the reproducer, > but comment #1 [1] in u

Bug#781795: pcre3: CVE-2015-2325: heap buffer overflow in compile_branch()

2015-04-03 Thread Salvatore Bonaccorso
Source: pcre3 Version: 1:8.30-5 Severity: important Tags: security upstream fixed-upstream Hi, the following vulnerability was published for pcre3. CVE-2015-2325[0]: heap buffer overflow in compile_branch() I was not able to reproduce the actual overflow with the reproducer, but comment #1 [1]