Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-6797

Опубликовано: 14 апр. 2018
Источник: redhat
CVSS3: 8.1

Описание

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

A heap buffer write overflow, with control over the bytes written, was found in the way regular expressions employing Unicode rules are compiled. An attacker, with the ability to provide a specially crafted regular expression, could crash the perl interpreter, or possibly execute arbitrary code.

Отчет

Versions of the perl interpreter older than 5.18 are not vulnerable. As a result, the versions of perl as shipped in Red Hat Enterprise Linux version 7, 6 and 5 are not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5perlNot affected
Red Hat Enterprise Linux 6perlNot affected
Red Hat Enterprise Linux 7perlNot affected
Red Hat Enterprise Linux 8perlNot affected
Red Hat Software Collectionsrh-perl520-perlWill not fix
Red Hat Software Collectionsrh-perl526-perlNot affected
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-perl524-perlFixedRHSA-2018:119223.04.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-perl524-perlFixedRHSA-2018:119223.04.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-perl524-perlFixedRHSA-2018:119223.04.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSrh-perl524-perlFixedRHSA-2018:119223.04.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1547783perl: heap write overflow in regcomp.c

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

CVSS3: 9.8
nvd
почти 8 лет назад

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

CVSS3: 9.8
debian
почти 8 лет назад

An issue was discovered in Perl 5.18 through 5.26. A crafted regular e ...

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

suse-cvrf
почти 8 лет назад

Security update for perl

8.1 High

CVSS3