Re: [exim-dev] PCRE vulnerability

Top Page
Delete this message
Reply to this message
Author: Andreas Metzler
Date:  
To: exim-dev
Subject: Re: [exim-dev] PCRE vulnerability
On 2005-08-23 Marc Haber <mh+exim-dev@???> wrote:
> Hi,


> On Tue, Aug 23, 2005 at 09:18:53AM +0100, Philip Hazel wrote:
> > The bug was fixed in PCRE 6.2, which is in the current Exim snapshot.


> Do I see correctly that the 4.50 from Debian stable and the 4.52 from
> Debian unstable/testing both have a vulnerable PCRE library?

[...]

As the Debian packages link dynamically against PCRE, there is nothing
that needs to be fixed there. We'll just need to wait for (or engage in
proving a) fixed libpcre3 package.

               cu andreas
-- 
"See, I told you they'd listen to Reason," [SPOILER] Svfurlr fnlf,
fuhggvat qbja gur juveyvat tha.
Neal Stephenson in "Snow Crash"