Re: [exim-dev] PCRE vulnerability

Top Page
Delete this message
Reply to this message
Author: Andreas Metzler
Date:  
To: exim-dev
Subject: Re: [exim-dev] PCRE vulnerability
On 2005-08-25 David Woodhouse <dwmw2@???> wrote:
> On Tue, 2005-08-23 at 12:57 +0200, Andreas Metzler wrote:
> > As the Debian packages link dynamically against PCRE, there is nothing
> > that needs to be fixed there.


> Hrm. That sounds like the right thing to do for the Fedora/Red Hat
> packages too. Are there restrictions on the version of PCRE which can be
> used?


> RHEL4 has pcre 4.5 and exim 4.43 (both with security patches), while
> I'll probably just update Fedora to Exim 4.52 (or 4.53 if that comes out
> in time).


Hello,
Afaik know exim only uses a safe subset of functionality. The static
version shipped with exim is (or at least used to be) stripped down.
So I guess anything starting with pcre 3 should work.

http://svn.debian.org/wsvn/pkg-exim4/exim/trunk/debian/patches/36_pcre.dpatch?op=file&rev=0&sc=0
                   cu andreas
-- 
"See, I told you they'd listen to Reason," [SPOILER] Svfurlr fnlf,
fuhggvat qbja gur juveyvat tha.
Neal Stephenson in "Snow Crash"