ALSA-2021:4373

Source
https://errata.almalinux.org/8/ALSA-2021-4373.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4373.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2021:4373
Related
Published
2021-11-09T09:12:45Z
Modified
2023-03-13T16:33:45Z
Summary
Low: pcre security update
Details

PCRE is a Perl-compatible regular expression library.

Security Fix(es):

  • pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1 (CVE-2019-20838)

  • pcre: Integer overflow when parsing callout numeric arguments (CVE-2020-14155)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

References

Affected packages

AlmaLinux:8 / pcre

Package

Name
pcre

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.42-6.el8

AlmaLinux:8 / pcre-cpp

Package

Name
pcre-cpp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.42-6.el8

AlmaLinux:8 / pcre-devel

Package

Name
pcre-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.42-6.el8

AlmaLinux:8 / pcre-static

Package

Name
pcre-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.42-6.el8

AlmaLinux:8 / pcre-utf16

Package

Name
pcre-utf16

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.42-6.el8

AlmaLinux:8 / pcre-utf32

Package

Name
pcre-utf32

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.42-6.el8