Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-6798

Опубликовано: 14 апр. 2018
Источник: redhat
CVSS3: 7.5

Описание

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.

A heap buffer over read flaw was found in the way Perl regular expression engine handled inputs with invalid UTF-8 characters. An attacker able to provide a specially crafted input to be matched against a regular expression could cause Perl interpreter to crash or disclose portion of its memory.

Отчет

Versions of the perl interpreter older than 5.22 are not vulnerable. As a result, the versions of perl as shipped in Red Hat Enterprise Linux version 7, 6 and 5, as well as the versions of rh-perl520-perl as shipped with Red Hat Software Collections are not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5perlNot affected
Red Hat Enterprise Linux 6perlNot affected
Red Hat Enterprise Linux 7perlNot affected
Red Hat Enterprise Linux 8perlNot affected
Red Hat Software Collectionsrh-perl520-perlNot affected
Red Hat Software Collectionsrh-perl526-perlNot affected
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-perl524-perlFixedRHSA-2018:119223.04.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-perl524-perlFixedRHSA-2018:119223.04.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-perl524-perlFixedRHSA-2018:119223.04.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSrh-perl524-perlFixedRHSA-2018:119223.04.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1547779perl: heap read overflow in regexec.c

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.

CVSS3: 7.5
nvd
почти 8 лет назад

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.

CVSS3: 7.5
debian
почти 8 лет назад

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted ...

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.

suse-cvrf
больше 1 года назад

Security update for perl

7.5 High

CVSS3