Red Hat Bugzilla – Bug 1500717
CVE-2017-8786 pcre2: Heap-based buffer overflow in pcre2test.c
Last modified: 2017-10-11 07:27:54 EDT
pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression. Upstream issue: https://bugs.exim.org/show_bug.cgi?id=2079 Upstream patches: https://vcs.pcre.org/pcre2?view=revision&revision=696 https://vcs.pcre.org/pcre2?view=revision&revision=697 References: https://blogs.gentoo.org/ago/2017/04/29/libpcre-heap-based-buffer-overflow-write-in-pcre2test-c/
Created mingw-pcre2 tracking bugs for this issue: Affects: fedora-26 [bug 1500718] Created pcre2 tracking bugs for this issue: Affects: epel-6 [bug 1500719]