Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 614054 (CVE-2017-7244)

Summary: <dev-libs/libpcre-8.41: invalid memory read in _pcre32_xclass (pcre_xclass.c)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: base-system
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://blogs.gentoo.org/ago/2017/03/20/libpcre-invalid-memory-read-in-_pcre32_xclass-pcre_xclass-c/
Whiteboard: A3 [glsa cve]
Package list:
Runtime testing required: ---
Bug Depends on: 614052    
Bug Blocks:    
Attachments:
Description Flags
Patch for CVE-2017-7244 none

Description Agostino Sarubbo gentoo-dev 2017-03-27 09:49:11 UTC
Details at $URL.


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Yury German Gentoo Infrastructure gentoo-dev 2017-03-28 04:34:12 UTC
A fuzz on libpcre1 through the pcretest utility revealed an invalid memory read. Upstream says that this bug is fixed by one of the previous commit. However I’m providing as usual the stacktrace and the reproducer, so if you are not running the latest upstream release, like happen on debian/rhel based distros, you may want to check better the status of this bug.
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-06-03 21:02:19 UTC
Created attachment 475122 [details, diff]
Patch  for CVE-2017-7244

Fixed in

> Revision: 1688
> Author: ph10
> Date: Friday, February 24, 2017 18:30:30
> Message:
> Fix Unicode property crash for 32-bit characters greater than 0x10ffff.
> 
> ----
> Modified : /code/trunk/ChangeLog
> Modified : /code/trunk/maint/MultiStage2.py
> Modified : /code/trunk/pcre_internal.h
> Modified : /code/trunk/pcre_ucd.c

(not yet released)
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2017-08-18 17:04:06 UTC
Fixed in >=dev-libs/libpcre-8.41, stabilization will happen in bug 614052.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2017-10-23 01:20:26 UTC
This issue was resolved and addressed in
 GLSA 201710-25 at https://security.gentoo.org/glsa/201710-25
by GLSA coordinator Aaron Bauman (b-man).