Bug 15918

Summary: pcre new security issues CVE-2015-2325 and CVE-2015-2326
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Mageia Bug Squad <bugsquad>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: bettycooper11it, bonjovi9x, mageia
Version: Cauldron   
Target Milestone: ---   
Hardware: i586   
OS: Linux   
URL: http://lwn.net/Vulnerabilities/644046/
Whiteboard:
Source RPM: pcre-8.36-2.mga5.src.rpm CVE:
Status comment:

Description David Walser 2015-05-12 19:27:54 CEST
OpenSuSE has issued an advisory today (May 12):
http://lists.opensuse.org/opensuse-updates/2015-05/msg00014.html

pcre 9.33 in Mageia 4 is not affected.

OpenSuSE updated to 9.37 to fix these issues.  The SuSE bugs also link upstream commits to fix them.

The URLs have changed and should be:
http://vcs.pcre.org/pcre?revision=1528&view=revision
http://vcs.pcre.org/pcre?revision=1529&view=revision

Reproducible: 

Steps to Reproduce:
Comment 1 Nicolas Lécureuil 2015-05-13 01:11:36 CEST
fixed on SVN and freeze push asked.

CC: (none) => mageia

Comment 2 David Walser 2015-05-13 15:39:43 CEST
pcre-8.37-1.mga5 uploaded for Cauldron.  Thanks Nicolas!

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Bon Jovi 2022-05-04 11:31:51 CEST

CC: (none) => bonjovi9x

Comment 3 Bon Jovi 2022-05-04 11:33:11 CEST Comment hidden (spam)
Comment 4 Betty Cooper 2022-07-28 04:01:29 CEST Comment hidden (spam)

CC: (none) => bettycooper11it