re2c: Buffer overflow — GLSA 202007-28

A vulnerability in re2c could lead to a Denial of Service condition.

Affected packages

dev-util/re2c on all architectures
Affected versions < 1.3-r1
Unaffected versions >= 1.3-r1

Background

re2c is a tool for generating C-based recognizers from regular expressions.

Description

A heap buffer overflow vulnerability was discovered in re2c.

Impact

An attacker could possibly cause a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All re2c users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-util/re2c-1.3-r1"
 

References

Release date
July 27, 2020

Latest revision
July 27, 2020: 1

Severity
normal

Exploitable
remote

Bugzilla entries