Title : Slackware Security Update Fixes PCRE Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2005-1582 CVE ID : CVE-2005-2491 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-08-31
Technical Description
Slackware has released updated packages to correct a vulnerability identified in PCRE. This flaw is due to an integer overflow error in "pcre_compile.c" when handling specially crafted regular expressions, which could be exploited by remote attackers (able to send regular expressions) to execute arbitrary commands with the privileges of the application using the vulnerable library. For additional information, see : VUPEN/ADV-2005-1511