漏洞信息详情
PCRE 超长UTF-8字符类 缓冲区溢出漏洞
- CNNVD编号:CNNVD-200802-323
- 危害等级: 高危
- CVE编号:
CVE-2008-0674
- 漏洞类型:
缓冲区溢出
- 发布时间:
2007-05-16
- 威胁类型:
远程
- 更新时间:
2008-10-23
- 厂 商:
pcre - 漏洞来源:
PCRE -
漏洞简介
PCRE(Perl Compatible Regular Expressions)是软件开发者Philip Hazel所研发的一个使用C语言编写的开源正则表达式函数库。
PCRE在处理字符类时存在缓冲区溢出漏洞。如果用户发送了codepoint大于255的超长UTF-8字符类的话,就可能触发这个溢出,导致执行任意指令。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
HTTP://www.debian.org/security/2008/dsa-1499
ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.6.tar.bz2
参考网址
来源: US-CERT
名称: TA09-218A
链接:http://www.us-cert.gov/cas/techalerts/TA09-218A.html
来源: bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=431660
来源: VUPEN
名称: ADV-2009-2172
链接:http://www.vupen.com/english/advisories/2009/2172
来源: SECTRACK
名称: 1022674
链接:http://www.securitytracker.com/id?1022674
来源: BID
名称: 31681
链接:http://www.securityfocus.com/bid/31681
来源: VUPEN
名称: ADV-2008-2780
链接:http://www.frsirt.com/english/advisories/2008/2780
来源: VUPEN
名称: ADV-2008-2268
链接:http://www.frsirt.com/english/advisories/2008/2268
来源: VUPEN
名称: ADV-2008-0570
链接:http://www.frsirt.com/english/advisories/2008/0570
来源: support.apple.com
链接:http://support.apple.com/kb/HT3757
来源: support.apple.com
链接:http://support.apple.com/kb/HT3216
来源: SECUNIA
名称: 36096
链接:http://secunia.com/advisories/36096
来源: SECUNIA
名称: 32222
链接:http://secunia.com/advisories/32222
来源: SECUNIA
名称: 31326
链接:http://secunia.com/advisories/31326
来源: pcre.org
链接:http://pcre.org/changelog.txt
来源: APPLE
名称: APPLE-SA-2009-08-05-1
链接:http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html
来源: APPLE
名称: APPLE-SA-2008-10-09
链接:http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
来源: APPLE
名称: APPLE-SA-2008-07-31
链接:http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html
来源: FEDORA
名称: FEDORA-2008-1842
链接:https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00181.html
来源: FEDORA
名称: FEDORA-2008-1783
链接:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00632.html
来源: FEDORA
名称: FEDORA-2008-1533
链接:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00371.html
来源: issues.rpath.com
链接:https://issues.rpath.com/browse/RPL-2503
来源: issues.rpath.com
链接:https://issues.rpath.com/browse/RPL-2223
来源: XF
名称: pcre-characterclass-bo(40505)
链接:http://xforce.iss.net/xforce/xfdb/40505
来源: UBUNTU
名称: USN-581-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-581-1
来源: BID
名称: 29009
链接:http://www.securityfocus.com/bid/29009
来源: BID
名称: 27786
链接:http://www.securityfocus.com/bid/27786
来源: BUGTRAQ
名称: 20080523 rPSA-2008-0176-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl
链接:http://www.securityfocus.com/archive/1/archive/1/492535/100/0/threaded
来源: BUGTRAQ
名称: 20080228 rPSA-2008-0086-1 pcre
链接:http://www.securityfocus.com/archive/1/archive/1/488927/100/0/threaded
来源: www.php.net
链接:http://www.php.net/ChangeLog-5.php
来源: MLIST
名称: [oss-security] 20080502 CVE Request (PHP)
链接:http://www.openwall.com/lists/oss-security/2008/05/02/2
来源: MANDRIVA
名称: MDVSA-2008:053
链接:http://www.mandriva.com/security/advisories?name=MDVSA-2008:053
来源: VUPEN
名称: ADV-2008-1412
链接:http://www.frsirt.com/english/advisories/2008/1412
来源: VUPEN
名称: ADV-2008-0592
链接:http://www.frsirt.com/english/advisories/2008/0592
来源: DEBIAN
名称: DSA-1499
链接:http://www.debian.org/security/2008/dsa-1499
来源: wiki.rpath.com
链接:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176
来源: wiki.rpath.com
链接:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0086
来源: wiki.rpath.com
链接:http://wiki.rpath.com/Advisories:rPSA-2008-0086
来源: GENTOO
名称: GLSA-200803-24
链接:http://security.gentoo.org/glsa/glsa-200803-24.xml
来源: SECUNIA
名称: 30345
链接:http://secunia.com/advisories/30345
来源: SECUNIA
名称: 30048
链接:http://secunia.com/advisories/30048
来源: SECUNIA
名称: 29282
链接:http://secunia.com/advisories/29282
来源: SECUNIA
名称: 29267
链接:http://secunia.com/advisories/29267
来源: SECUNIA
名称: 29175
链接:http://secunia.com/advisories/29175
来源: SECUNIA
名称: 29048
链接:http://secunia.com/advisories/29048
来源: SECUNIA
名称: 29027
链接:http://secunia.com/advisories/29027
来源: SECUNIA
名称: 28996