Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2016.0204
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2016-0204)
Resumen:The remote host is missing an update for the 'pcre' package(s) announced via the MGASA-2016-0204 advisory.
Descripción:Summary:
The remote host is missing an update for the 'pcre' package(s) announced via the MGASA-2016-0204 advisory.

Vulnerability Insight:
Updated pcre packages fix security vulnerabilities:

The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles a
paricular pattern and related patterns with named subgroups, which allows
remote attackers to cause a denial of service (heap-based buffer overflow)
or possibly have unspecified other impact via a crafted regular expression
(CVE-2016-1283).

The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39
mishandles patterns containing an (*ACCEPT) substring in conjunction with
nested parentheses, which allows remote attackers to execute arbitrary
code or cause a denial of service (stack-based buffer overflow) via a
crafted regular expression (CVE-2016-3191).

The pcre package has been updated to the latest CVS as of May 21, 2016,
aka 8.39-RC1, which fixes these issues, as well as several other bugs,
and possible security issues.

Affected Software/OS:
'pcre' package(s) on Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-1283
BugTraq ID: 79825
http://www.securityfocus.com/bid/79825
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178193.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178955.html
https://security.gentoo.org/glsa/201607-02
RedHat Security Advisories: RHSA-2016:1132
https://access.redhat.com/errata/RHSA-2016:1132
http://www.securitytracker.com/id/1034555
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.343110
Common Vulnerability Exposure (CVE) ID: CVE-2016-3191
BugTraq ID: 84810
http://www.securityfocus.com/bid/84810
RedHat Security Advisories: RHSA-2016:1025
http://rhn.redhat.com/errata/RHSA-2016-1025.html
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.