CVE-2015-2305
php5 - security update
EPSS 8.4%
描述
Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.
如何修補 CVE-2015-2305
要修補 CVE-2015-2305,請將受影響套件升級到下列已修補版本。
- Debian/clamav—升級至 0.98.7+dfsg-1 或更新版本
- Debian/librcsb-core-wrapper—升級至 1.005-3 或更新版本
- Debian/newlib—升級至 2.0.0-1 或更新版本
- —升級至 1.81.6-13 或更新版本
- —升級至 5.3.3.1-7+squeeze29 或更新版本
- —升級至 0.016-24 或更新版本
CVE-2015-2305 正在被利用嗎?
中等 — EPSS 為 8.4%,可持續追蹤但非最高優先。
受影響套件(6)
- from 0, < 0.98.7+dfsg-1
- from 0, < 1.005-3
- from 0, < 2.0.0-1
- from 0, < 1.81.6-13
- from 0, < 5.3.3.1-7+squeeze29
- from 0, < 0.016-24