An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.
{
"binaries": [
{
"binary_name": "erlang",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-asn1",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-base",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-base-hipe",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-common-test",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-corba",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-crypto",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-debugger",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-dev",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-dialyzer",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-diameter",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-edoc",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-eldap",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-erl-docgen",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-et",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-eunit",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-examples",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-gs",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-ic",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-ic-java",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-inets",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-jinterface",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-manpages",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-megaco",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-mnesia",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-mode",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-nox",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-observer",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-odbc",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-os-mon",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-parsetools",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-percept",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-public-key",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-reltool",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-runtime-tools",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-snmp",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-src",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-ssh",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-ssl",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-syntax-tools",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-test-server",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-tools",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-typer",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-webtool",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-wx",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-x11",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
},
{
"binary_name": "erlang-xmerl",
"binary_version": "1:18.3-dfsg-1ubuntu3.1"
}
],
"availability": "No subscription required"
}