|
Mandriva- Advisories MDVSA-2008:147: Updated pcre packages fix vulnerability
Advisories MDVSA-2008:147: Updated pcre packages fix vulnerability
Tavis Ormandy of the Google Security Team discovered a heap-based buffer overflow when compiling certain regular expression patterns. This could be used by a malicious attacker by sending a specially crafted regular expression to an application using the PCRE library, resulting in the possible execution of arbitrary code or a denial of service (CVE-2008-2371). The updated packages have been patched to correct this issue.
http://mandrivausers.org/index.php?showtopic=63624
http://mandrivausers.org/index.php?showtopic=63624
Wed, 16 Jul 2008 07:29:21 +0000
|