Debian Security Advisory
DSA-1020-1 flex -- buffer overflow
- Date Reported:
- 28 Mar 2006
- Affected Packages:
- flex
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2006-0459.
- More information:
-
Chris Moore discovered that flex, a scanner generator, generates code, which allocates insufficient memory, if the grammar contains REJECT statements or trailing context rules. This may lead to a buffer overflow and the execution of arbitrary code.
If you use code, which is derived from a vulnerable lex grammar in an untrusted environment you need to regenerate your scanner with the fixed version of flex.
The old stable distribution (woody) is not affected by this problem.
For the stable distribution (sarge) this problem has been fixed in version 2.5.31-31sarge1.
For the unstable distribution (sid) this problem has been fixed in version 2.5.33-1.
We recommend that you upgrade your flex package.
- Fixed in:
-
Debian GNU/Linux 3.1 (sarge)
- Source:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1.dsc
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1.diff.gz
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31.orig.tar.gz
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1.diff.gz
- Architecture-independent component:
- http://security.debian.org/pool/updates/main/f/flex/flex-doc_2.5.31-31sarge1_all.deb
- Alpha:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_alpha.deb
- AMD64:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_amd64.deb
- ARM:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_ia64.deb
- HPPA:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/f/flex/flex_2.5.31-31sarge1_sparc.deb
MD5 checksums of the listed files are available in the original advisory.