﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
6890	Vulnerabilities in pcre-8.37.	ken@…	ken@…	"Pcre-8.37 contains multiple buffer-overruns, at least one has a CVE (CVE-2015-3210) and is apparently exploitable, see [https://lists.exim.org/lurker/message/20150821.053519.d948ae8f.en.html] - I confirm the example there crashes pcretest as claimed. These have been fixed upstream in what will become 8.38. Unfortunately, 8.38 has not yet been released.

Arch are patching to fix this - see [https://bugs.archlinux.org/task/45207] and [https://projects.archlinux.org/svntogit/packages.git/tree/trunk?h=packages/pcre] where they are using a 135K patch.

Fedora apply six patches totalling 21K, some of which are backported [http://pkgs.fedoraproject.org/cgit/pcre.git/tree/].

I think we should go with the fedora patches ?"	defect	closed	high	7.8	BOOK	SVN	high	fixed		
