<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for pcre</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2016:2805-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-11-15T13:43:11Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-11-15T13:43:11Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-11-15T13:43:11Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for pcre</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This version fixes a number of vulnerabilities that affect pcre
and applications using the libary when accepting untrusted input
as regular expressions or as part thereof. Remote attackers could
have caused the application to crash, disclose information or
potentially execute arbitrary code.

- Update to PCRE 8.39 FATE#320298 boo#972127.
- CVE-2015-3210: heap buffer overflow in pcre_compile2() / compile_regex() (boo#933288)
- CVE-2015-3217: pcre: PCRE Library Call Stack Overflow Vulnerability in match() (boo#933878)
- CVE-2015-5073: pcre: Library Heap Overflow Vulnerability in find_fixedlength() (boo#936227)
- boo#942865: heap overflow in compile_regex()
- CVE-2015-8380: pcre: heap overflow in pcre_exec (boo#957566)
- boo#957598: various security issues fixed in pcre 8.37 and 8.38 release
- CVE-2016-1283: pcre: Heap buffer overflow in pcre_compile2 causes DoS (boo#960837)
- CVE-2016-3191: pcre: workspace overflow for (*ACCEPT) with deeply nested parentheses (boo#971741)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>http://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html</URL>
      <Description>E-Mail link for openSUSE-SU-2016:2805-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE 13.2">
      <Branch Type="Product Name" Name="openSUSE 13.2">
        <FullProductName ProductID="openSUSE 13.2">openSUSE 13.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libpcre1-8.39-3.8.1">
      <FullProductName ProductID="libpcre1-8.39-3.8.1">libpcre1-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcre1-32bit-8.39-3.8.1">
      <FullProductName ProductID="libpcre1-32bit-8.39-3.8.1">libpcre1-32bit-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcre1-debuginfo-8.39-3.8.1">
      <FullProductName ProductID="libpcre1-debuginfo-8.39-3.8.1">libpcre1-debuginfo-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcre1-debuginfo-32bit-8.39-3.8.1">
      <FullProductName ProductID="libpcre1-debuginfo-32bit-8.39-3.8.1">libpcre1-debuginfo-32bit-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcre16-0-8.39-3.8.1">
      <FullProductName ProductID="libpcre16-0-8.39-3.8.1">libpcre16-0-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcre16-0-32bit-8.39-3.8.1">
      <FullProductName ProductID="libpcre16-0-32bit-8.39-3.8.1">libpcre16-0-32bit-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcre16-0-debuginfo-8.39-3.8.1">
      <FullProductName ProductID="libpcre16-0-debuginfo-8.39-3.8.1">libpcre16-0-debuginfo-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcre16-0-debuginfo-32bit-8.39-3.8.1">
      <FullProductName ProductID="libpcre16-0-debuginfo-32bit-8.39-3.8.1">libpcre16-0-debuginfo-32bit-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcrecpp0-8.39-3.8.1">
      <FullProductName ProductID="libpcrecpp0-8.39-3.8.1">libpcrecpp0-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcrecpp0-32bit-8.39-3.8.1">
      <FullProductName ProductID="libpcrecpp0-32bit-8.39-3.8.1">libpcrecpp0-32bit-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcrecpp0-debuginfo-8.39-3.8.1">
      <FullProductName ProductID="libpcrecpp0-debuginfo-8.39-3.8.1">libpcrecpp0-debuginfo-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcrecpp0-debuginfo-32bit-8.39-3.8.1">
      <FullProductName ProductID="libpcrecpp0-debuginfo-32bit-8.39-3.8.1">libpcrecpp0-debuginfo-32bit-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcreposix0-8.39-3.8.1">
      <FullProductName ProductID="libpcreposix0-8.39-3.8.1">libpcreposix0-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcreposix0-32bit-8.39-3.8.1">
      <FullProductName ProductID="libpcreposix0-32bit-8.39-3.8.1">libpcreposix0-32bit-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcreposix0-debuginfo-8.39-3.8.1">
      <FullProductName ProductID="libpcreposix0-debuginfo-8.39-3.8.1">libpcreposix0-debuginfo-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcreposix0-debuginfo-32bit-8.39-3.8.1">
      <FullProductName ProductID="libpcreposix0-debuginfo-32bit-8.39-3.8.1">libpcreposix0-debuginfo-32bit-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-8.39-3.8.1">
      <FullProductName ProductID="pcre-8.39-3.8.1">pcre-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-debugsource-8.39-3.8.1">
      <FullProductName ProductID="pcre-debugsource-8.39-3.8.1">pcre-debugsource-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-devel-8.39-3.8.1">
      <FullProductName ProductID="pcre-devel-8.39-3.8.1">pcre-devel-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-devel-static-8.39-3.8.1">
      <FullProductName ProductID="pcre-devel-static-8.39-3.8.1">pcre-devel-static-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-doc-8.39-3.8.1">
      <FullProductName ProductID="pcre-doc-8.39-3.8.1">pcre-doc-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-tools-8.39-3.8.1">
      <FullProductName ProductID="pcre-tools-8.39-3.8.1">pcre-tools-8.39-3.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-tools-debuginfo-8.39-3.8.1">
      <FullProductName ProductID="pcre-tools-debuginfo-8.39-3.8.1">pcre-tools-debuginfo-8.39-3.8.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libpcre1-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcre1-8.39-3.8.1">libpcre1-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-32bit-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcre1-32bit-8.39-3.8.1">libpcre1-32bit-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-debuginfo-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcre1-debuginfo-8.39-3.8.1">libpcre1-debuginfo-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-debuginfo-32bit-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcre1-debuginfo-32bit-8.39-3.8.1">libpcre1-debuginfo-32bit-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcre16-0-8.39-3.8.1">libpcre16-0-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-32bit-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcre16-0-32bit-8.39-3.8.1">libpcre16-0-32bit-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-debuginfo-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcre16-0-debuginfo-8.39-3.8.1">libpcre16-0-debuginfo-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-debuginfo-32bit-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcre16-0-debuginfo-32bit-8.39-3.8.1">libpcre16-0-debuginfo-32bit-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcrecpp0-8.39-3.8.1">libpcrecpp0-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-32bit-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcrecpp0-32bit-8.39-3.8.1">libpcrecpp0-32bit-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-debuginfo-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcrecpp0-debuginfo-8.39-3.8.1">libpcrecpp0-debuginfo-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-debuginfo-32bit-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcrecpp0-debuginfo-32bit-8.39-3.8.1">libpcrecpp0-debuginfo-32bit-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcreposix0-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcreposix0-8.39-3.8.1">libpcreposix0-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcreposix0-32bit-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcreposix0-32bit-8.39-3.8.1">libpcreposix0-32bit-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcreposix0-debuginfo-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcreposix0-debuginfo-8.39-3.8.1">libpcreposix0-debuginfo-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcreposix0-debuginfo-32bit-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:libpcreposix0-debuginfo-32bit-8.39-3.8.1">libpcreposix0-debuginfo-32bit-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:pcre-8.39-3.8.1">pcre-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-debugsource-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:pcre-debugsource-8.39-3.8.1">pcre-debugsource-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-devel-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:pcre-devel-8.39-3.8.1">pcre-devel-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-devel-static-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:pcre-devel-static-8.39-3.8.1">pcre-devel-static-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-doc-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:pcre-doc-8.39-3.8.1">pcre-doc-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-tools-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:pcre-tools-8.39-3.8.1">pcre-tools-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-tools-debuginfo-8.39-3.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:pcre-tools-debuginfo-8.39-3.8.1">pcre-tools-debuginfo-8.39-3.8.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P&lt;B&gt;c)(?P&lt;B&gt;a(?P=B)))&gt;WGXCREDITS)/, a different vulnerability than CVE-2015-8384.</Note>
    </Notes>
    <CVE>CVE-2015-3210</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:libpcre1-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-debugsource-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-static-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-doc-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-debuginfo-8.39-3.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3210.html</URL>
        <Description>CVE-2015-3210</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/933288</URL>
        <Description>SUSE Bug 933288</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.</Note>
    </Notes>
    <CVE>CVE-2015-3217</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:libpcre1-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-debugsource-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-static-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-doc-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-debuginfo-8.39-3.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3217.html</URL>
        <Description>CVE-2015-3217</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/933878</URL>
        <Description>SUSE Bug 933878</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.</Note>
    </Notes>
    <CVE>CVE-2015-5073</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:libpcre1-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-debugsource-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-static-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-doc-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-debuginfo-8.39-3.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-5073.html</URL>
        <Description>CVE-2015-5073</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936227</URL>
        <Description>SUSE Bug 936227</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8380</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:libpcre1-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-debugsource-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-static-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-doc-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-debuginfo-8.39-3.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8380.html</URL>
        <Description>CVE-2015-8380</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957566</URL>
        <Description>SUSE Bug 957566</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'&lt;((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2016-1283</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:libpcre1-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-debugsource-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-static-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-doc-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-debuginfo-8.39-3.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1283.html</URL>
        <Description>CVE-2016-1283</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/960837</URL>
        <Description>SUSE Bug 960837</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, aka ZDI-CAN-3542.</Note>
    </Notes>
    <CVE>CVE-2016-3191</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:libpcre1-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre1-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcre16-0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcrecpp0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-32bit-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:libpcreposix0-debuginfo-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-debugsource-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-devel-static-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-doc-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-8.39-3.8.1</ProductID>
        <ProductID>openSUSE 13.2:pcre-tools-debuginfo-8.39-3.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3191.html</URL>
        <Description>CVE-2016-3191</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/971741</URL>
        <Description>SUSE Bug 971741</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
