- --------------------------------------------------------------------- Red Hat Security Advisory
Synopsis: Moderate: pcre security update Advisory ID: RHSA-2007:1065-01 Advisory URL: https://rhn.redhat.com/errata/RHSA-2007-1065.html Issue date: 2007-11-29 Updated on: 2007-11-29 Product: Red Hat Enterprise Linux CVE Names: CVE-2006-7228 CVE-2007-1660 - ---------------------------------------------------------------------
1. Summary:
Updated pcre packages that resolve several security issues are now available for Red Hat Enterprise Linux 2.1.
This update has been rated as having moderate security impact by the Red Hat Security Response Team.
2. Relevant releases/architectures:
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386
3. Problem description:
PCRE is a Perl-compatible regular expression library.
Flaws were discovered in the way PCRE handles certain malformed regular expressions. If an application linked against PCRE parses a malicious regular expression, it may have been possible to run arbitrary code as the user running the application. (CVE-2006-7228, CVE-2007-1660)
Users of PCRE are advised to upgrade to these updated packages, which contain backported patches to resolve these issues.
Red Hat would like to thank Ludwig Nussel for reporting these issues.
4. Solution:
Before applying this update, make sure that all previously-released errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at http://kbase.redhat.com/faq/FAQ_58_10188