Mehrere Probleme in PCRE
ID: | USN-2943-1 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.10 |
Datum: | Mi, 30. März 2016, 07:11 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8387 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8380 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2325 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8384 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8386 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5073 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2327 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8390 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1283 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2326 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8388 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8389 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9769 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3210 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8391 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8395 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2328 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8381 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8383 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8392 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8393 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8394 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8385 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8382 |
Applikationen: | PCRE |
Originalnachricht |
|
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============1407467293280692318== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="FjgDiHITwxsjtbeHujOoeR2AI303lTxTa" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --FjgDiHITwxsjtbeHujOoeR2AI303lTxTa Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-2943-1 March 29, 2016 pcre3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: PCRE could be made to crash or run programs if it processed a specially-crafted regular expression. Software Description: - pcre3: Perl 5 Compatible Regular Expression Library Details: It was discovered that PCRE incorrectly handled certain regular expressions. A remote attacker could use this issue to cause applications using PCRE to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: libpcre3 2:8.35-7.1ubuntu1.3 Ubuntu 14.04 LTS: libpcre3 1:8.31-2ubuntu2.2 Ubuntu 12.04 LTS: libpcre3 8.12-4ubuntu0.2 After a standard system update you need to restart applications using PCRE, such as the Apache HTTP server and Nginx, to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2943-1 CVE-2014-9769, CVE-2015-2325, CVE-2015-2326, CVE-2015-2327, CVE-2015-2328, CVE-2015-3210, CVE-2015-5073, CVE-2015-8380, CVE-2015-8381, CVE-2015-8382, CVE-2015-8383, CVE-2015-8384, CVE-2015-8385, CVE-2015-8386, CVE-2015-8387, CVE-2015-8388, CVE-2015-8389, CVE-2015-8390, CVE-2015-8391, CVE-2015-8392, CVE-2015-8393, CVE-2015-8394, CVE-2015-8395, CVE-2016-1283, CVE-2016-3191 Package Information: https://launchpad.net/ubuntu/+source/pcre3/2:8.35-7.1ubuntu1.3 https://launchpad.net/ubuntu/+source/pcre3/1:8.31-2ubuntu2.2 https://launchpad.net/ubuntu/+source/pcre3/8.12-4ubuntu0.2 --FjgDiHITwxsjtbeHujOoeR2AI303lTxTa Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJW+r9VAAoJEGVp2FWnRL6TIoMQAIg+MCMIcrEAGxmrukm5Ub5z WKNCNLxvv5o9KACUs04zHYOQIqt74YOnmCZP8UDlH6gNdiF0GnJ/T8zmDOxv4+pN nS0bdh2VP8bP7qkyL3/93i5463RpdgRjBQMbXYOmH7idlrvGkn1x4s3Nlq7CsB2e UJ4WhNKgXAJEHFeI0NXEd1Ih0sfhTviIHLcG3p+8hYuebUeb+RtVufrwXMasMtXO j+n8Qt3HDWu5l+W0Rhi1Otz49h69qg3xO9C9i3cG/q23tEGUXh7n+cmyJQT9n/jJ nIY6DDokMZ89gWl7Ghd23ycBhc0wZdV4BAm6nCCYKSsTZAQUJ4hVpZ9ynDI2xbiM uTbCHv4rDkaD86dIJf717ooffoCfrGhPq+7djiiZZMGXbJ3v59u+K2ll43GccVfI y67OwWrRse2zbBA2dRL0HCeIWFbxZE3shkiPSLpBhHkY3pNk2JWcy7/7H45dPCGh 7hPHTniZSRfq9AXjZm1bN0JUjOA13nZHRffGDcbRxoYf6BrV6LzlkooBsrg1USGY V8ARyekZt0n0dfV3vi0WGm9ZtAWzXRMGwNxwqXyenx0T47Ay/dhpvCxq8dmaRPiQ j3DEmPWrzA8yIxURL45rCQm9GVk6U+O8uGSq8YJcZarZJA5flCH+zg7jdZXUcwdJ Okr5dvKoJ4UIw8xQKr+E =yj2f -----END PGP SIGNATURE----- --FjgDiHITwxsjtbeHujOoeR2AI303lTxTa-- --===============1407467293280692318== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce --===============1407467293280692318==-- |