Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-47100

Опубликовано: 03 дек. 2023
Источник: redhat
CVSS3: 0
EPSS Низкий

Описание

In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.

A flaw was found in Perl due to improper handling of the property name by the S_parse_uniprop_string function in regcomp.c. This issue could allow an attacker to to bypass security restrictions and use a specially crafted regular expression input to write to unallocated space.

Отчет

This flaw was found to be a duplicate of CVE-2023-47038. Please see https://access.redhat.com/security/cve/CVE-2023-47038 for information about affected products and security errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perlNot affected
Red Hat Enterprise Linux 7perlNot affected
Red Hat Enterprise Linux 8perlNot affected
Red Hat Enterprise Linux 8perl:5.32/perlNot affected
Red Hat Enterprise Linux 9perlNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-755

EPSS

Процентиль: 21%
0.00066
Низкий

0 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 1 года назад

In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.

CVSS3: 9.8
nvd
больше 1 года назад

In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.

CVSS3: 9.8
debian
больше 1 года назад

In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write t ...

CVSS3: 9.8
github
больше 1 года назад

In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.

CVSS3: 9.8
fstec
больше 1 года назад

Уязвимость функции S_parse_uniprop_string файла regcomp.c интерпретатора языка программирования Perl, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 21%
0.00066
Низкий

0 Low

CVSS3