Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12558

Опубликовано: 19 июн. 2018
Источник: redhat
CVSS3: 7.5

Описание

The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7perl-Email-AddressWill not fix
Red Hat Enterprise Linux 8perl-Email-AddressNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1593318perl-Email-Address: Specially crafted input could cause Denial of Service due to complex parse() method

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").

CVSS3: 7.5
nvd
больше 7 лет назад

The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").

CVSS3: 7.5
debian
больше 7 лет назад

The parse() method in the Email::Address module through 1.909 for Perl ...

suse-cvrf
почти 7 лет назад

Security update for perl-Email-Address

CVSS3: 7.5
github
больше 3 лет назад

The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").

7.5 High

CVSS3