Publishing details

Changelog

pcre3 (1:8.31-2ubuntu2.2) trusty-security; urgency=medium

  * SECURITY UPDATE: fix multiple security issues by applying patches
    from Debian jessie package:
    - 0001-Fix-overflow-when-ovector-has-size-1.patch
    - 794589-information-disclosure.patch
    - 0001-Fix-buffer-overflow-for-lookbehind-within-mutually-r.patch
    - 0001-Add-integer-overflow-check-to-n-code.patch
    - 0001-Fix-bug-for-classes-containing-sequences.patch
    - 0001-Fix-run-for-ever-bug-for-deeply-nested-sequences.patch
    - 0001-Make-pcregrep-q-override-l-and-c-for-compatibility-w.patch
    - 0001-Add-missing-integer-overflow-checks.patch
    - 0001-Fix-compile-time-loop-for-recursive-reference-within.patch
    - 0001-Fix-named-forward-reference-to-duplicate-group-numbe.patch
    - CVE-2015-2328, CVE-2015-8380, CVE-2015-8382, CVE-2015-8385,
      CVE-2015-8386, CVE-2015-8387, CVE-2015-8390, CVE-2015-8391,
      CVE-2015-8393, CVE-2015-8394
  * SECURITY UPDATE: denial of service via pattern containing (*ACCEPT)
    substring with nested parantheses
    - debian/patches/apply-upstream-revision-1631-closes-8159: fix
      workspace overflow for (*ACCEPT) with deeply nested parentheses in
      pcreposix.c, pcre_compile.c, pcre_internal.h, add tests to
      testdata/testoutput11-8, testdata/testoutput11-16,
      testdata/testinput11.
    - CVE-2016-3191
  * debian/rules: set make check to verbose.

 -- Marc Deslauriers <email address hidden>  Fri, 25 Mar 2016 07:55:28 -0400

Available diffs

Builds

Built packages

Package files