Re: PCRE Character Class Codepoints UTF-8 Buffer Overflow Vulnerability

Urs Janßen <[email protected]> Sat, 22 Mar 2008 13:22:42 +0100
Newsgroups gmane.network.tin.devel
Message-ID <[email protected]>
On Sat, Mar 22, 2008 at 01:11:17PM +0100, Sven Gottwald wrote:
> is tin affected by the "PCRE Character Class Codepoints UTF-8 Buffer
> Overflow Vulnerability" described in
> <URL:http://www.frsirt.com/english/advisories/2008/0570>?

as tin allows user-input which is pass to pcre (e.g. filter file) - how
could it now be affected?

> The bug is
> fixed in PCRE version 7.6 <URL:http://www.pcre.org/changelog.txt>.

feel free so send a patch which will updated the included pcre version

urs
-- 
"Only whimps use tape backup: _real_ men just upload their important stuff
 on ftp, and let the rest of the world mirror it ;)" - Linus