PCRE Regular Expression Library Multiple Integer and Buffer Overflow Vulnerabilities
BID:26462
Info
PCRE Regular Expression Library Multiple Integer and Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26462 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-7228 CVE-2006-7227 CVE-2005-4872 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2007 12:00AM |
| Updated: | Dec 15 2008 01:41PM |
| Credit: | Chris Evans is credited with the discovery of these issues. |
| Vulnerable: |
VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 2.5.5 patch 4 VMWare ESX Server 2.5.4 patch 15 VMWare ESX Server 3.5 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux Enterprise Server 10.SP1 SuSE Linux Desktop 1.0 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4.6.z Redhat Enterprise Linux ES 4.5.z Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4.6.z Redhat Enterprise Linux AS 4.5.z Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 R Foundation R 2.2.1 PCRE PCRE 6.2 PCRE PCRE 6.1 PCRE PCRE 6.0 PCRE PCRE 5.0 PCRE PCRE 4.5 PCRE PCRE 4.4 PCRE PCRE 3.9 PCRE PCRE 3.7 PCRE PCRE 3.4 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Kazehakase Kazehakase 0.4.2 Gentoo x11-libs/goffice 0.6 Gentoo www-client/kazehakase 0.4.9 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 CHICKEN CHICKEN 3.0 Avaya SES 3.1.2 Avaya SES 3.1.1 Avaya SES 4.0 Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX 2.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya CCS 3.1.2 Avaya CCS 3.1.1 Avaya CCS 4.0 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.3 Avaya AES 4.0 |
| Not Vulnerable: |
R Foundation R 2.2.1-r1 PCRE PCRE 7.3 PCRE PCRE 6.7 Gentoo x11-libs/goffice 0.6.1 Gentoo www-client/kazehakase 0.5 CHICKEN CHICKEN 3.1 |
Discussion
PCRE Regular Expression Library Multiple Integer and Buffer Overflow Vulnerabilities
PCRE regular-expression library is prone to multiple integer- and buffer-overflow vulnerabilities.
Attackers can exploit these issues to execute arbitrary code, cause denial-of-service conditions, or launch other attacks in the context of the application using the affected library.
PCRE regular-expression library is prone to multiple integer- and buffer-overflow vulnerabilities.
Attackers can exploit these issues to execute arbitrary code, cause denial-of-service conditions, or launch other attacks in the context of the application using the affected library.
Exploit / POC
PCRE Regular Expression Library Multiple Integer and Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PCRE Regular Expression Library Multiple Integer and Buffer Overflow Vulnerabilities
Solution:
These issues have been addressed in PCRE 6.7 and later. Please see the referenced advisories for more information and advisories.
VMWare ESX Server 3.5
PCRE PCRE 3.4
PCRE PCRE 3.9
PCRE PCRE 4.4
PCRE PCRE 5.0
PCRE PCRE 6.0
PCRE PCRE 6.1
PCRE PCRE 6.2
Solution:
These issues have been addressed in PCRE 6.7 and later. Please see the referenced advisories for more information and advisories.
VMWare ESX Server 3.5
-
VMWare ESX350-200803214-UG
http://download3.vmware.com/software/esx/ESX350-200803214-UG.zip
PCRE PCRE 3.4
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 3.9
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 4.4
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 5.0
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 6.0
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 6.1
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
PCRE PCRE 6.2
-
PCRE pcre-7.4.tar.gz
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.4.tar.gz
References
PCRE Regular Expression Library Multiple Integer and Buffer Overflow Vulnerabilities
References:
References:
- CESA-2007-006 - rev 1 pcre integer / buffer overflows (Chris Evans [email protected])
- PCRE Homepage (PCRE)
- ASA-2007-493 - pcre security update (RHSA-2007-1052) (Avaya)
- ASA-2007-504 - PCRE security update (RHSA-2007-1063) (Avaya)
- ASA-2007-505 PCRE security update (RHSA-2007-1068) (Avaya)
- ASA-2008-017 - python security update (RHSA-2007-1077) (Avaya)
- RHSA-2007:1052-4 Critical: pcre security update (Red Hat)
- RHSA-2007:1063-4 - pcre security update (RedHat)
- RHSA-2007:1065-3 - pcre security update (RedHat)
- RHSA-2007:1068-3: pcre security update (Red Hat)
- RHSA-2007:1076-6 python security update (Red Hat)
- RHSA-2007:1077-5 python security update (Red Hat)
- RHSA-2008:0546-3 Moderate: php security update (Red Hat)
- SUSE Security Advisory SUSE-SA:2008:004 (SUSE)
- VMware ESX Server 3.5, Patch ESX350-200802408-SG: Security Updates to the Python (VMware)