Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:5251

Опубликовано: 28 июн. 2022
Источник: rocky
Оценка: Moderate

Описание

Moderate: pcre2 security update

The pcre2 package contains a new generation of the Perl Compatible Regular Expression libraries for implementing regular expression pattern matching using the same syntax and semantics as Perl.

Security Fix(es):

  • pcre2: Out-of-bounds read in compile_xclass_matchingpath in pcre2_jit_compile.c (CVE-2022-1586)

  • pcre2: Out-of-bounds read in get_recurse_data_length in pcre2_jit_compile.c (CVE-2022-1587)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
pcre2i6865.el9_0pcre2-10.37-5.el9_0.i686.rpm
pcre2x86_645.el9_0pcre2-10.37-5.el9_0.x86_64.rpm
pcre2-syntaxnoarch5.el9_0pcre2-syntax-10.37-5.el9_0.noarch.rpm
pcre2-syntaxnoarch5.el9_0pcre2-syntax-10.37-5.el9_0.noarch.rpm
pcre2-syntaxnoarch5.el9_0pcre2-syntax-10.37-5.el9_0.noarch.rpm
pcre2-syntaxnoarch5.el9_0pcre2-syntax-10.37-5.el9_0.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
больше 3 лет назад

ELSA-2022-5251: pcre2 security update (MODERATE)

CVSS3: 9.1
ubuntu
больше 3 лет назад

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.

CVSS3: 7.5
redhat
больше 3 лет назад

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.

CVSS3: 9.1
nvd
больше 3 лет назад

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.

CVSS3: 9.1
msrc
больше 3 лет назад

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.