Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAOSkqBXPt+6POW6s7s5mck_bZGgpfP142O5UvyVN9F-7wY1i7Q@mail.gmail.com>
Date: Fri, 5 Jun 2015 08:55:24 +0800
From: Guanxing Wen <wengx522@...il.com>
To: felipensp@...il.com
Cc: oss-security@...ts.openwall.com, taviso@...gle.com
Subject: Re: Re: Re: Re: Re: Re: CVE-2015-3217: PCRE Library Call Stack
 Overflow Vulnerability in match()

Thanks for your explanation.
 It has also been confirmed from PHP that this is not a bug of their
product:

"
We cannot do much for it.
Increase the stack of your server (apache has an option for that for
example) or simplify your regex.
One should really not feed pcre with custom inputs :)
"

Cheers, Wen.
----org----

AFAIK this is not a bug on PHP at all, this is a long time known issue
on PCRE lib instead.
Check the documentation for futher
details:http://pcre.org/current/doc/html/pcre2stack.html

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.