Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2939

Опубликовано: 09 авг. 2011
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4perlAffected
Red Hat Enterprise Linux 5perlAffected
Red Hat Enterprise Linux 6perlFixedRHSA-2011:142403.11.2011

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=731246Perl decode_xs heap-based buffer overflow

EPSS

Процентиль: 84%
0.02324
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.

nvd
больше 13 лет назад

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.

debian
больше 13 лет назад

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in th ...

github
больше 3 лет назад

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.

CVSS3: 5.6
fstec
больше 13 лет назад

Уязвимость функции decode_xs интерпретатора языка программирования Perl, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 84%
0.02324
Низкий

5.1 Medium

CVSS2