Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-18311

Опубликовано: 29 нояб. 2018
Источник: redhat
CVSS3: 8.1
EPSS Средний

Описание

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

Отчет

This vulnerability is present in versions of perl included with Red Hat Virtualization Hypervisor and Management Appliance, however it is not exposed in any meaningful way. Perl is only included in these images as a dependency of components which do not manipulate ENV, and are not exposed to user input. A future update may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5perlWill not fix
Red Hat Enterprise Linux 6perlWill not fix
Red Hat Enterprise Linux 8perlNot affected
Red Hat Enterprise Linux 8perl:5.24/perlNot affected
Red Hat OpenShift Enterprise 3perlNot affected
Red Hat Virtualization 4redhat-virtualization-hostWill not fix
Red Hat Virtualization 4rhvm-applianceWill not fix
Red Hat Enterprise Linux 7perlFixedRHSA-2019:010921.01.2019
Red Hat Enterprise Linux 7.3 Advanced Update SupportperlFixedRHSA-2019:240007.08.2019
Red Hat Enterprise Linux 7.3 Telco Extended Update SupportperlFixedRHSA-2019:240007.08.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190->CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1646730perl: Integer overflow leading to buffer overflow in Perl_my_setenv()

EPSS

Процентиль: 93%
0.11355
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

CVSS3: 9.8
nvd
около 7 лет назад

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

CVSS3: 9.8
debian
около 7 лет назад

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via ...

suse-cvrf
больше 6 лет назад

Security update for perl

CVSS3: 9.8
github
больше 3 лет назад

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

EPSS

Процентиль: 93%
0.11355
Средний

8.1 High

CVSS3