REDHAT-BUG-1187225: Low severity php pcre extension vulnerability
It was reported that pcreexec in PHP pcre extension partially initialize a buffer when an invalid regex is processed, which can information disclosure.
A mitigation fix have been applied in PHP 5.4+ http://git.php.net/?p=php-src.git;a=commitdiff;h=c351b47ce85a3a147cfa801fa9f0149ab4160834
Upstream bug report (with a patch proposal): http://bugs.exim.org/showbug.cgi?id=1537
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1187225?
REDHAT-BUG-1187225 has a potential for information disclosure due to improper buffer initialization.
How do I fix REDHAT-BUG-1187225?
To fix REDHAT-BUG-1187225, upgrade the PHP PCRE extension to version 5.4 or higher.
What software is affected by REDHAT-BUG-1187225?
The vulnerability REDHAT-BUG-1187225 affects the PHP PCRE extension versions up to but not including 5.4.
What causes the vulnerability REDHAT-BUG-1187225?
The vulnerability REDHAT-BUG-1187225 is caused by the pcre_exec function partially initializing a buffer when processing an invalid regex.
Is there any mitigation for REDHAT-BUG-1187225?
Yes, a mitigation fix has been applied in PHP version 5.4 and above for REDHAT-BUG-1187225.