CVE-2015-2325 (retired)

Priority
Description
heap buffer overflow in compile_branch()
Notes
 tyhicks> Unable to trigger the overflow in Vivid, Utopic, or Trusty.
 sarnold> seyeongkim reports that he was able to reproduce the issue
  on vivid and wily
 mdeslaur> valgrind does show an invalid read, even if it doesn't end in
 mdeslaur> a crash
 mdeslaur> can't reproduce on precise
 mdeslaur>
 mdeslaur> was supposed to be fixed in wily (2:8.35-7ubuntu2) but got
 mdeslaur> reverted in (2:8.35-7ubuntu5) by mistake
 mdeslaur>
 mdeslaur> CVE-2015-2325_CVE-2015-2326_CVE-2015-3210_CVE-2015-5073.patch
 mdeslaur> in jessie
Assigned-to
mdeslaur
Package
Source: pcre3 (LP Ubuntu Debian)
Upstream:needed
Ubuntu 14.04 LTS (Trusty Tahr):released (1:8.31-2ubuntu2.1)
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (2:8.38-3)
Patches:
Upstream:http://vcs.pcre.org/pcre?view=revision&revision=1528
More Information

Updated: 2019-03-26 12:14:49 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)