Bug 315881 (CVE-2007-1660) - CVE-2007-1660 pcre regular expression flaws
Summary: CVE-2007-1660 pcre regular expression flaws
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-1660
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 315951 315961 315971 315981 378401 381991 382081 411731 413871 414271 445917
Blocks: 307451
TreeView+ depends on / blocked
 
Reported: 2007-10-02 19:37 UTC by Josh Bressers
Modified: 2023-05-11 12:27 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-01-14 13:36:16 UTC
Embargoed:


Attachments (Terms of Use)
Patch backported to pcre-3.9 in EL3 (2.15 KB, patch)
2007-11-15 16:41 UTC, Tomas Hoger
no flags Details | Diff
Patch backported to pcre-3.4 in EL2.1 (2.81 KB, patch)
2007-11-16 17:20 UTC, Tomas Hoger
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:0967 0 normal SHIPPED_LIVE Critical: pcre security update 2007-11-05 16:46:02 UTC
Red Hat Product Errata RHSA-2007:0968 0 normal SHIPPED_LIVE Critical: pcre security update 2008-01-08 17:54:13 UTC
Red Hat Product Errata RHSA-2007:1063 0 normal SHIPPED_LIVE Important: pcre security update 2007-11-29 14:56:28 UTC
Red Hat Product Errata RHSA-2007:1065 0 normal SHIPPED_LIVE Moderate: pcre security update 2007-11-29 14:58:42 UTC
Red Hat Product Errata RHSA-2008:0546 0 normal SHIPPED_LIVE Moderate: php security update 2008-07-16 09:59:22 UTC

Description Josh Bressers 2007-10-02 19:37:46 UTC
Tavis Ormandy of the Google Security Team reported multiple pcre regular
expressions flaws.  Here are the details pasted from Tavis' mail:

CVE-2007-1660:
multiple forms of character class had their sizes miscalculated on
initial passes, resulting in too little memory being allocated, this
was also inadvertently fixed in version 7.0, where the compile phase
was entirely re-engineered (and much improved, from a security
standpoint).

Acknowledgements:

Red Hat would like to thank Tavis Ormandy and Will Drewry for properly disclosing these issues.

Comment 7 Josh Bressers 2007-11-05 16:05:14 UTC
Lifting embargo

Comment 8 Tomas Hoger 2007-11-15 16:41:29 UTC
Created attachment 259991 [details]
Patch backported to pcre-3.9 in EL3

Comment 10 Tomas Hoger 2007-11-16 17:20:21 UTC
Created attachment 261501 [details]
Patch backported to pcre-3.4 in EL2.1


Note You need to log in before you can comment on or make changes to this bug.