PCRE Regular Expression Library UTF-8 Options Multiple Remote Denial of Service Vulnerabilities
BID:26550
Info
PCRE Regular Expression Library UTF-8 Options Multiple Remote Denial of Service Vulnerabilities
| Bugtraq ID: | 26550 |
| Class: | Design Error |
| CVE: |
CVE-2006-7230 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2007 12:00AM |
| Updated: | May 13 2008 12:05AM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 R Foundation R 2.2.1 PCRE PCRE 6.2 PCRE PCRE 6.1 PCRE PCRE 6.0 PCRE PCRE 5.0 PCRE PCRE 4.5 PCRE PCRE 4.4 PCRE PCRE 3.9 PCRE PCRE 3.7 PCRE PCRE 3.4 PCRE PCRE 6.7 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Kazehakase Kazehakase 0.4.2 Gentoo x11-libs/goffice 0.6 Gentoo www-client/kazehakase 0.4.9 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 CHICKEN CHICKEN 3.0 Avaya SES 3.1.2 Avaya SES 3.1.1 Avaya SES 4.0 Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Intuity AUDIX LX 2.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya CCS 3.1.2 Avaya CCS 3.1.1 Avaya CCS 4.0 Avaya CCS 3.1 Avaya Aura Application Enablement Services 4.0.1 Avaya AES 4.0 |
| Not Vulnerable: |
R Foundation R 2.2.1-r1 PCRE PCRE 7.0 Gentoo x11-libs/goffice 0.6.1 Gentoo www-client/kazehakase 0.5 CHICKEN CHICKEN 3.1 |
Discussion
PCRE Regular Expression Library UTF-8 Options Multiple Remote Denial of Service Vulnerabilities
PCRE regular-expression library is prone to multiple remote denial-of-service vulnerabilities because a memory-calculation error occurs for certain regular expressions.
Successful exploits may allow remote attackers to cause denial-of-service conditions on computers running the affected library.
These issues affect versions prior to PCRE 7.0.
PCRE regular-expression library is prone to multiple remote denial-of-service vulnerabilities because a memory-calculation error occurs for certain regular expressions.
Successful exploits may allow remote attackers to cause denial-of-service conditions on computers running the affected library.
These issues affect versions prior to PCRE 7.0.
Exploit / POC
PCRE Regular Expression Library UTF-8 Options Multiple Remote Denial of Service Vulnerabilities
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PCRE Regular Expression Library UTF-8 Options Multiple Remote Denial of Service Vulnerabilities
Solution:
The vendor has released upgrades to address these issues; please see the references for details.
Solution:
The vendor has released upgrades to address these issues; please see the references for details.
References
PCRE Regular Expression Library UTF-8 Options Multiple Remote Denial of Service Vulnerabilities
References:
References: