PCRE 超长UTF-8字符类 缓冲区溢出漏洞

漏洞信息详情

PCRE 超长UTF-8字符类 缓冲区溢出漏洞

漏洞简介

PCRE(Perl Compatible Regular Expressions)是软件开发者Philip Hazel所研发的一个使用C语言编写的开源正则表达式函数库。

PCRE在处理字符类时存在缓冲区溢出漏洞。如果用户发送了codepoint大于255的超长UTF-8字符类的话,就可能触发这个溢出,导致执行任意指令。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

HTTP://www.debian.org/security/2008/dsa-1499

ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-7.6.tar.bz2

参考网址

来源: US-CERT

名称: TA09-218A

链接:http://www.us-cert.gov/cas/techalerts/TA09-218A.html

来源: bugzilla.redhat.com

链接:https://bugzilla.redhat.com/show_bug.cgi?id=431660

来源: VUPEN

名称: ADV-2009-2172

链接:http://www.vupen.com/english/advisories/2009/2172

来源: SECTRACK

名称: 1022674

链接:http://www.securitytracker.com/id?1022674

来源: BID

名称: 31681

链接:http://www.securityfocus.com/bid/31681

来源: VUPEN

名称: ADV-2008-2780

链接:http://www.frsirt.com/english/advisories/2008/2780

来源: VUPEN

名称: ADV-2008-2268

链接:http://www.frsirt.com/english/advisories/2008/2268

来源: VUPEN

名称: ADV-2008-0570

链接:http://www.frsirt.com/english/advisories/2008/0570

来源: support.apple.com

链接:http://support.apple.com/kb/HT3757

来源: support.apple.com

链接:http://support.apple.com/kb/HT3216

来源: SECUNIA

名称: 36096

链接:http://secunia.com/advisories/36096

来源: SECUNIA

名称: 32222

链接:http://secunia.com/advisories/32222

来源: SECUNIA

名称: 31326

链接:http://secunia.com/advisories/31326

来源: pcre.org

链接:http://pcre.org/changelog.txt

来源: APPLE

名称: APPLE-SA-2009-08-05-1

链接:http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html

来源: APPLE

名称: APPLE-SA-2008-10-09

链接:http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html

来源: APPLE

名称: APPLE-SA-2008-07-31

链接:http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html

来源: FEDORA

名称: FEDORA-2008-1842

链接:https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00181.html

来源: FEDORA

名称: FEDORA-2008-1783

链接:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00632.html

来源: FEDORA

名称: FEDORA-2008-1533

链接:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00371.html

来源: issues.rpath.com

链接:https://issues.rpath.com/browse/RPL-2503

来源: issues.rpath.com

链接:https://issues.rpath.com/browse/RPL-2223

来源: XF

名称: pcre-characterclass-bo(40505)

链接:http://xforce.iss.net/xforce/xfdb/40505

来源: UBUNTU

名称: USN-581-1

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-581-1

来源: BID

名称: 29009

链接:http://www.securityfocus.com/bid/29009

来源: BID

名称: 27786

链接:http://www.securityfocus.com/bid/27786

来源: BUGTRAQ

名称: 20080523 rPSA-2008-0176-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl

链接:http://www.securityfocus.com/archive/1/archive/1/492535/100/0/threaded

来源: BUGTRAQ

名称: 20080228 rPSA-2008-0086-1 pcre

链接:http://www.securityfocus.com/archive/1/archive/1/488927/100/0/threaded

来源: www.php.net

链接:http://www.php.net/ChangeLog-5.php

来源: MLIST

名称: [oss-security] 20080502 CVE Request (PHP)

链接:http://www.openwall.com/lists/oss-security/2008/05/02/2

来源: MANDRIVA

名称: MDVSA-2008:053

链接:http://www.mandriva.com/security/advisories?name=MDVSA-2008:053

来源: VUPEN

名称: ADV-2008-1412

链接:http://www.frsirt.com/english/advisories/2008/1412

来源: VUPEN

名称: ADV-2008-0592

链接:http://www.frsirt.com/english/advisories/2008/0592

来源: DEBIAN

名称: DSA-1499

链接:http://www.debian.org/security/2008/dsa-1499

来源: wiki.rpath.com

链接:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176

来源: wiki.rpath.com

链接:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0086

来源: wiki.rpath.com

链接:http://wiki.rpath.com/Advisories:rPSA-2008-0086

来源: GENTOO

名称: GLSA-200803-24

链接:http://security.gentoo.org/glsa/glsa-200803-24.xml

来源: SECUNIA

名称: 30345

链接:http://secunia.com/advisories/30345

来源: SECUNIA

名称: 30048

链接:http://secunia.com/advisories/30048

来源: SECUNIA

名称: 29282

链接:http://secunia.com/advisories/29282

来源: SECUNIA

名称: 29267

链接:http://secunia.com/advisories/29267

来源: SECUNIA

名称: 29175

链接:http://secunia.com/advisories/29175

来源: SECUNIA

名称: 29048

链接:http://secunia.com/advisories/29048

来源: SECUNIA

名称: 29027

链接:http://secunia.com/advisories/29027

来源: SECUNIA

名称: 28996

链接:http://secunia.com/advisories/

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享