<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for pcre</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2016:2971-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-12-02T10:43:31Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-12-02T10:43:31Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-12-02T10:43:31Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for pcre</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update for pcre to version 8.39 (bsc#972127) fixes several issues.

If you use pcre extensively please be aware that this is an update to a new version. Please
make sure that your software works with the updated version.

This version fixes a number of vulnerabilities that affect pcre
and applications using the libary when accepting untrusted input
as regular expressions or as part thereof. Remote attackers could
have caused the application to crash, disclose information or
potentially execute arbitrary code. These security issues were fixed:

- CVE-2014-8964: Heap-based buffer overflow in PCRE allowed remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats (bsc#906574).
- CVE-2015-2325: Heap buffer overflow in compile_branch() (bsc#924960).
- CVE-2015-3210: Heap buffer overflow in pcre_compile2() / compile_regex() (bsc#933288)
- CVE-2015-3217: PCRE Library Call Stack Overflow Vulnerability in match() (bsc#933878).
- CVE-2015-5073: Library Heap Overflow Vulnerability in find_fixedlength() (bsc#936227).
- bsc#942865: heap overflow in compile_regex()
- CVE-2015-8380: The pcre_exec function in pcre_exec.c mishandled a // pattern with a \01 string, which allowed remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror (bsc#957566).
- CVE-2015-2327: PCRE mishandled certain patterns with internal recursive back references, which allowed remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror (bsc#957567).
- bsc#957598: Various security issues 
- CVE-2015-8381: Heap Overflow in compile_regex() (bsc#957598).
- CVE-2015-8382: Regular Expression Uninitialized Pointer Information Disclosure Vulnerability (ZDI-CAN-2547)(bsc#957598).
- CVE-2015-8383: Buffer overflow caused by repeated conditional group(bsc#957598).
- CVE-2015-8384: Buffer overflow caused by recursive back reference by name within certain group(bsc#957598).
- CVE-2015-8385: Buffer overflow caused by forward reference by name to certain group(bsc#957598).
- CVE-2015-8386: Buffer overflow caused by lookbehind assertion(bsc#957598).
- CVE-2015-8387: Integer overflow in subroutine calls(bsc#957598).
- CVE-2015-8388: Buffer overflow caused by certain patterns with an unmatched closing parenthesis(bsc#957598).
- CVE-2015-8389: Infinite recursion in JIT compiler when processing certain patterns(bsc#957598).
- CVE-2015-8390: Reading from uninitialized memory when processing certain patterns(bsc#957598).
- CVE-2015-8391: Some pathological patterns causes pcre_compile() to run for a very long time(bsc#957598).
- CVE-2015-8392: Buffer overflow caused by certain patterns with duplicated named groups(bsc#957598).
- CVE-2015-8393: Information leak when running pcgrep -q on crafted binary(bsc#957598).
- CVE-2015-8394: Integer overflow caused by missing check for certain conditions(bsc#957598).
- CVE-2015-8395: Buffer overflow caused by certain references(bsc#957598).
- CVE-2015-2328: PCRE mishandled the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allowed remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression (bsc#957600).
- CVE-2016-1283: The pcre_compile2 function in pcre_compile.c in PCRE mishandled certain patterns with named subgroups, which allowed remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression (bsc#960837).
- CVE-2016-3191: The compile_branch function in pcre_compile.c in pcre2_compile.c mishandled patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allowed remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted regular expression (bsc#971741).

These non-security issues were fixed:
- JIT compiler improvements
- performance improvements
- The Unicode data tables have been updated to Unicode 7.0.0.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-SLE-DESKTOP-12-SP1-2016-1744,SUSE-SLE-DESKTOP-12-SP2-2016-1744,SUSE-SLE-HA-12-SP1-2016-1744,SUSE-SLE-HA-12-SP2-2016-1744,SUSE-SLE-RPI-12-SP2-2016-1744,SUSE-SLE-SDK-12-SP1-2016-1744,SUSE-SLE-SDK-12-SP2-2016-1744,SUSE-SLE-SERVER-12-SP1-2016-1744,SUSE-SLE-SERVER-12-SP2-2016-1744,SUSE-SLE-WE-12-SP1-2016-1744,SUSE-SLE-WE-12-SP2-2016-1744</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      <Description>Link for SUSE-SU-2016:2971-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2016-December/002436.html</URL>
      <Description>E-Mail link for SUSE-SU-2016:2971-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/906574</URL>
      <Description>SUSE Bug 906574</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/924960</URL>
      <Description>SUSE Bug 924960</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/933288</URL>
      <Description>SUSE Bug 933288</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/933878</URL>
      <Description>SUSE Bug 933878</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/936227</URL>
      <Description>SUSE Bug 936227</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/942865</URL>
      <Description>SUSE Bug 942865</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/957566</URL>
      <Description>SUSE Bug 957566</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/957567</URL>
      <Description>SUSE Bug 957567</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/957598</URL>
      <Description>SUSE Bug 957598</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/957600</URL>
      <Description>SUSE Bug 957600</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/960837</URL>
      <Description>SUSE Bug 960837</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/971741</URL>
      <Description>SUSE Bug 971741</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/972127</URL>
      <Description>SUSE Bug 972127</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-8964/</URL>
      <Description>SUSE CVE CVE-2014-8964 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-2325/</URL>
      <Description>SUSE CVE CVE-2015-2325 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-2327/</URL>
      <Description>SUSE CVE CVE-2015-2327 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-2328/</URL>
      <Description>SUSE CVE CVE-2015-2328 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3210/</URL>
      <Description>SUSE CVE CVE-2015-3210 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3217/</URL>
      <Description>SUSE CVE CVE-2015-3217 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-5073/</URL>
      <Description>SUSE CVE CVE-2015-5073 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8380/</URL>
      <Description>SUSE CVE CVE-2015-8380 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8381/</URL>
      <Description>SUSE CVE CVE-2015-8381 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8382/</URL>
      <Description>SUSE CVE CVE-2015-8382 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8383/</URL>
      <Description>SUSE CVE CVE-2015-8383 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8384/</URL>
      <Description>SUSE CVE CVE-2015-8384 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8385/</URL>
      <Description>SUSE CVE CVE-2015-8385 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8386/</URL>
      <Description>SUSE CVE CVE-2015-8386 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8387/</URL>
      <Description>SUSE CVE CVE-2015-8387 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8388/</URL>
      <Description>SUSE CVE CVE-2015-8388 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8389/</URL>
      <Description>SUSE CVE CVE-2015-8389 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8390/</URL>
      <Description>SUSE CVE CVE-2015-8390 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8391/</URL>
      <Description>SUSE CVE CVE-2015-8391 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8392/</URL>
      <Description>SUSE CVE CVE-2015-8392 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8393/</URL>
      <Description>SUSE CVE CVE-2015-8393 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8394/</URL>
      <Description>SUSE CVE CVE-2015-8394 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-8395/</URL>
      <Description>SUSE CVE CVE-2015-8395 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1283/</URL>
      <Description>SUSE CVE CVE-2016-1283 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-3191/</URL>
      <Description>SUSE CVE CVE-2016-3191 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1" CPE="cpe:/o:suse:sled:12:sp1">SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2" CPE="cpe:/o:suse:sled:12:sp2">SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Availability Extension 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Availability Extension 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 12 SP1" CPE="cpe:/o:suse:sle-ha:12:sp1">SUSE Linux Enterprise High Availability Extension 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Availability Extension 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Availability Extension 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 12 SP2" CPE="cpe:/o:suse:sle-ha:12:sp2">SUSE Linux Enterprise High Availability Extension 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1" CPE="cpe:/o:suse:sles:12:sp1">SUSE Linux Enterprise Server 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2" CPE="cpe:/o:suse:sles:12:sp2">SUSE Linux Enterprise Server 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2" CPE="cpe:/o:suse:sles:12:sp2">SUSE Linux Enterprise Server for Raspberry Pi 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1" CPE="cpe:/o:suse:sles_sap:12:sp1">SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2" CPE="cpe:/o:suse:sles_sap:12:sp2">SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP1" CPE="cpe:/o:suse:sle-sdk:12:sp1">SUSE Linux Enterprise Software Development Kit 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP2" CPE="cpe:/o:suse:sle-sdk:12:sp2">SUSE Linux Enterprise Software Development Kit 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Workstation Extension 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12 SP1" CPE="cpe:/o:suse:sle-we:12:sp1">SUSE Linux Enterprise Workstation Extension 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Workstation Extension 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12 SP2" CPE="cpe:/o:suse:sle-we:12:sp2">SUSE Linux Enterprise Workstation Extension 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libpcre1-8.39-5.1">
      <FullProductName ProductID="libpcre1-8.39-5.1">libpcre1-8.39-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcre1-32bit-8.39-5.1">
      <FullProductName ProductID="libpcre1-32bit-8.39-5.1">libpcre1-32bit-8.39-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcre16-0-8.39-5.1">
      <FullProductName ProductID="libpcre16-0-8.39-5.1">libpcre16-0-8.39-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcrecpp0-8.39-5.1">
      <FullProductName ProductID="libpcrecpp0-8.39-5.1">libpcrecpp0-8.39-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcrecpp0-32bit-8.39-5.1">
      <FullProductName ProductID="libpcrecpp0-32bit-8.39-5.1">libpcrecpp0-32bit-8.39-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpcreposix0-8.39-5.1">
      <FullProductName ProductID="libpcreposix0-8.39-5.1">libpcreposix0-8.39-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-devel-8.39-5.1">
      <FullProductName ProductID="pcre-devel-8.39-5.1">pcre-devel-8.39-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-devel-static-8.39-5.1">
      <FullProductName ProductID="pcre-devel-static-8.39-5.1">pcre-devel-static-8.39-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="pcre-tools-8.39-5.1">
      <FullProductName ProductID="pcre-tools-8.39-5.1">pcre-tools-8.39-5.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libpcre1-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1">libpcre1-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1">libpcre1-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1">libpcre16-0-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1">libpcrecpp0-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1">libpcrecpp0-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1">libpcre1-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1">libpcre1-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1">libpcre16-0-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1">libpcrecpp0-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1">libpcrecpp0-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcreposix0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Availability Extension 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1">libpcreposix0-8.39-5.1 as a component of SUSE Linux Enterprise High Availability Extension 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcreposix0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Availability Extension 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1">libpcreposix0-8.39-5.1 as a component of SUSE Linux Enterprise High Availability Extension 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1">libpcre1-8.39-5.1 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1">libpcre1-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1">libpcre16-0-8.39-5.1 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1">libpcre1-8.39-5.1 as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1">libpcre1-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1">libpcre16-0-8.39-5.1 as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1">libpcre1-8.39-5.1 as a component of SUSE Linux Enterprise Server for Raspberry Pi 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1">libpcre16-0-8.39-5.1 as a component of SUSE Linux Enterprise Server for Raspberry Pi 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1">libpcre1-8.39-5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1">libpcre1-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1">libpcre16-0-8.39-5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1">libpcre1-8.39-5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre1-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1">libpcre1-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcre16-0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1">libpcre16-0-8.39-5.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1">libpcrecpp0-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcreposix0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1">libpcreposix0-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-devel-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1">pcre-devel-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-devel-static-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1">pcre-devel-static-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-tools-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1">pcre-tools-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1">libpcrecpp0-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcreposix0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1">libpcreposix0-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-devel-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1">pcre-devel-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-devel-static-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1">pcre-devel-static-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="pcre-tools-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1">pcre-tools-8.39-5.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1">libpcrecpp0-8.39-5.1 as a component of SUSE Linux Enterprise Workstation Extension 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1">libpcrecpp0-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Workstation Extension 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1">libpcrecpp0-8.39-5.1 as a component of SUSE Linux Enterprise Workstation Extension 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpcrecpp0-32bit-8.39-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1">libpcrecpp0-32bit-8.39-5.1 as a component of SUSE Linux Enterprise Workstation Extension 12 SP2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.</Note>
    </Notes>
    <CVE>CVE-2014-8964</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-8964.html</URL>
        <Description>CVE-2014-8964</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/906574</URL>
        <Description>SUSE Bug 906574</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924960</URL>
        <Description>SUSE Bug 924960</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/933288</URL>
        <Description>SUSE Bug 933288</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936408</URL>
        <Description>SUSE Bug 936408</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.</Note>
    </Notes>
    <CVE>CVE-2015-2325</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-2325.html</URL>
        <Description>CVE-2015-2325</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924960</URL>
        <Description>SUSE Bug 924960</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/933288</URL>
        <Description>SUSE Bug 933288</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936408</URL>
        <Description>SUSE Bug 936408</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.36 mishandles the /(((a\2)|(a*)\g&lt;-1&gt;))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-2327</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-2327.html</URL>
        <Description>CVE-2015-2327</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/906574</URL>
        <Description>SUSE Bug 906574</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957567</URL>
        <Description>SUSE Bug 957567</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-2328</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-2328.html</URL>
        <Description>CVE-2015-2328</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/906574</URL>
        <Description>SUSE Bug 906574</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957600</URL>
        <Description>SUSE Bug 957600</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P&lt;B&gt;c)(?P&lt;B&gt;a(?P=B)))&gt;WGXCREDITS)/, a different vulnerability than CVE-2015-8384.</Note>
    </Notes>
    <CVE>CVE-2015-3210</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3210.html</URL>
        <Description>CVE-2015-3210</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/933288</URL>
        <Description>SUSE Bug 933288</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.</Note>
    </Notes>
    <CVE>CVE-2015-3217</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3217.html</URL>
        <Description>CVE-2015-3217</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/933878</URL>
        <Description>SUSE Bug 933878</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.</Note>
    </Notes>
    <CVE>CVE-2015-5073</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-5073.html</URL>
        <Description>CVE-2015-5073</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936227</URL>
        <Description>SUSE Bug 936227</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8380</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8380.html</URL>
        <Description>CVE-2015-8380</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957566</URL>
        <Description>SUSE Bug 957566</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|((?'R')))H'Rk'Rf)|s(?'R'))))/ and /(?J:(?|(:(?|(?'R')(\z(?|(?'R')(\k'R')|((?'R')))k'R')|((?'R')))H'Ak'Rf)|s(?'R')))/ patterns, and related patterns with certain group references, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8381</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8381.html</URL>
        <Description>CVE-2015-8381</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/906574</URL>
        <Description>SUSE Bug 906574</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (partially initialized memory and application crash) via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, aka ZDI-CAN-2547.</Note>
    </Notes>
    <CVE>CVE-2015-8382</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8382.html</URL>
        <Description>CVE-2015-8382</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8383</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8383.html</URL>
        <Description>CVE-2015-8383</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8392 and CVE-2015-8395.</Note>
    </Notes>
    <CVE>CVE-2015-8384</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8384.html</URL>
        <Description>CVE-2015-8384</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/906574</URL>
        <Description>SUSE Bug 906574</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8385</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8385.html</URL>
        <Description>CVE-2015-8385</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8386</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8386.html</URL>
        <Description>CVE-2015-8386</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8387</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8387.html</URL>
        <Description>CVE-2015-8387</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles the /(?=di(?&lt;=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8388</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8388.html</URL>
        <Description>CVE-2015-8388</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936227</URL>
        <Description>SUSE Bug 936227</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8389</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8389.html</URL>
        <Description>CVE-2015-8389</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8390</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8390.html</URL>
        <Description>CVE-2015-8390</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8391</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8391.html</URL>
        <Description>CVE-2015-8391</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion and buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8384 and CVE-2015-8395.</Note>
    </Notes>
    <CVE>CVE-2015-8392</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8392.html</URL>
        <Description>CVE-2015-8392</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/906574</URL>
        <Description>SUSE Bug 906574</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.</Note>
    </Notes>
    <CVE>CVE-2015-8393</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8393.html</URL>
        <Description>CVE-2015-8393</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles the (?(&lt;digits&gt;) and (?(R&lt;digits&gt;) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2015-8394</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8394.html</URL>
        <Description>CVE-2015-8394</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8384 and CVE-2015-8392.</Note>
    </Notes>
    <CVE>CVE-2015-8395</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-8395.html</URL>
        <Description>CVE-2015-8395</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/906574</URL>
        <Description>SUSE Bug 906574</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/957598</URL>
        <Description>SUSE Bug 957598</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/958373</URL>
        <Description>SUSE Bug 958373</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'&lt;((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.</Note>
    </Notes>
    <CVE>CVE-2016-1283</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1283.html</URL>
        <Description>CVE-2016-1283</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/960837</URL>
        <Description>SUSE Bug 960837</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, aka ZDI-CAN-3542.</Note>
    </Notes>
    <CVE>CVE-2016-3191</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre1-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpcre16-0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP1:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:libpcreposix0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-devel-static-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:pcre-tools-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP1:libpcrecpp0-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-32bit-8.39-5.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP2:libpcrecpp0-8.39-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20162971-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3191.html</URL>
        <Description>CVE-2016-3191</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/971741</URL>
        <Description>SUSE Bug 971741</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
