[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2015:2111-07 -- Redhat grep

ID: oval:org.secpod.oval:def:501697Date: (C)2015-11-25   (M)2023-11-10
Class: PATCHFamily: unix




The grep utility searches through textual input for lines that contain a match to a specified pattern and then prints the matching lines. The GNU grep utilities include grep, egrep, and fgrep. A heap-based buffer overflow flaw was found in the way grep processed certain pattern and text combinations. An attacker able to trick a user into running grep on specially crafted input could use this flaw to crash grep or, potentially, read from uninitialized memory. This update also fixes the following bugs: * Prior to this update, the \w and \W symbols were inconsistently matched to the [:alnum:] character class. Consequently, using regular expressions with "\w" and "\W" could lead to incorrect results. With this update, "\w" is consistently matched to the [_[:alnum:]] character, and "\W" is consistently matched to the [^_[:alnum:]] character. * Previously, the Perl Compatible Regular Expression matcher did not work correctly when matching non-UTF-8 text in UTF-8 locales. Consequently, an error message about invalid UTF-8 byte sequence characters was returned. To fix this bug, patches from upstream have been applied to the grep utility. As a result, PCRE now skips non-UTF-8 characters as non-matching text without returning any error message. All grep users are advised to upgrade to these updated packages, which contain backported patches to correct these issues.

Platform:
Red Hat Enterprise Linux 7
Product:
grep
Reference:
RHSA-2015:2111-07
CVE-2015-1345
CVE    1
CVE-2015-1345
CPE    5
cpe:/a:gnu:grep:2.19
cpe:/o:redhat:enterprise_linux:7
cpe:/a:gnu:grep:2.21
cpe:/a:gnu:grep:2.20
...

© SecPod Technologies