Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 614054 (CVE-2017-7244) - <dev-libs/libpcre-8.41: invalid memory read in _pcre32_xclass (pcre_xclass.c)
Summary: <dev-libs/libpcre-8.41: invalid memory read in _pcre32_xclass (pcre_xclass.c)
Status: RESOLVED FIXED
Alias: CVE-2017-7244
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://blogs.gentoo.org/ago/2017/03/...
Whiteboard: A3 [glsa cve]
Keywords:
Depends on: CVE-2017-7245, CVE-2017-7246
Blocks:
  Show dependency tree
 
Reported: 2017-03-27 09:49 UTC by Agostino Sarubbo
Modified: 2017-10-23 01:20 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Patch for CVE-2017-7244 (CVE-2017-7244.patch,13.30 KB, patch)
2017-06-03 21:02 UTC, Thomas Deutschmann (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-03-27 09:49:11 UTC
Details at $URL.


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Yury German Gentoo Infrastructure gentoo-dev 2017-03-28 04:34:12 UTC
A fuzz on libpcre1 through the pcretest utility revealed an invalid memory read. Upstream says that this bug is fixed by one of the previous commit. However I’m providing as usual the stacktrace and the reproducer, so if you are not running the latest upstream release, like happen on debian/rhel based distros, you may want to check better the status of this bug.
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-06-03 21:02:19 UTC
Created attachment 475122 [details, diff]
Patch  for CVE-2017-7244

Fixed in

> Revision: 1688
> Author: ph10
> Date: Friday, February 24, 2017 18:30:30
> Message:
> Fix Unicode property crash for 32-bit characters greater than 0x10ffff.
> 
> ----
> Modified : /code/trunk/ChangeLog
> Modified : /code/trunk/maint/MultiStage2.py
> Modified : /code/trunk/pcre_internal.h
> Modified : /code/trunk/pcre_ucd.c

(not yet released)
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2017-08-18 17:04:06 UTC
Fixed in >=dev-libs/libpcre-8.41, stabilization will happen in bug 614052.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2017-10-23 01:20:26 UTC
This issue was resolved and addressed in
 GLSA 201710-25 at https://security.gentoo.org/glsa/201710-25
by GLSA coordinator Aaron Bauman (b-man).