Advisories ยป MGASA-2022-0417

Updated pcre packages fix security vulnerability

Publication date: 13 Nov 2022
Modification date: 13 Nov 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-1586 , CVE-2022-1587

Description

An out-of-bounds read vulnerability was discovered in the PCRE2 library in
the compile_xclass_matchingpath() function of the pcre2_jit_compile.c
file. This involves a unicode property matching issue in JIT-compiled
regular expressions. The issue occurs because the character was not fully
read in case-less matching within JIT. (CVE-2022-1586)

An out-of-bounds read vulnerability was discovered in the PCRE2 library in
the get_recurse_data_length() function of the pcre2_jit_compile.c file.
This issue affects recursions in JIT-compiled regular expressions caused
by duplicate data transfers. (CVE-2022-1587)
                

References

SRPMS

8/core