|
Family: Gentoo Local Security Checks --> Category: infos
[GLSA-200508-17] libpcre: Heap integer overflow Vulnerability Scan
Vulnerability Scan Summary libpcre: Heap integer overflow
Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200508-17
(libpcre: Heap integer overflow)
libpcre fails to check certain quantifier values in regular
expressions for sane values.
Impact
A possible hacker could possibly exploit this vulnerability to execute
arbitrary code by sending specially crafted regular expressions to
applications making use of the libpcre library.
Workaround
There is no known workaround at this time.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491
http://www.securitytracker.com/alerts/2005/Aug/1014744.html
Solution:
All libpcre users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/libpcre-6.3"
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|