ALAS2-2021-1610

Related Vulnerabilities: CVE-2020-10543   CVE-2020-10878   CVE-2020-12723  

Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. (CVE-2020-10543) Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. (CVE-2020-10878) regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. (CVE-2020-12723)

ALAS2-2021-1610


Amazon Linux 2 Security Advisory: ALAS-2021-1610
Advisory Release Date: 2021-02-19 01:26 Pacific
Advisory Updated Date: 2021-02-19 22:02 Pacific
Severity: Medium

Issue Overview:

Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. (CVE-2020-10543)

Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. (CVE-2020-10878)

regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. (CVE-2020-12723)


Affected Packages:

perl


Issue Correction:
Run yum update perl to update your system.

New Packages:
aarch64:
    perl-5.16.3-299.amzn2.0.1.aarch64
    perl-libs-5.16.3-299.amzn2.0.1.aarch64
    perl-devel-5.16.3-299.amzn2.0.1.aarch64
    perl-macros-5.16.3-299.amzn2.0.1.aarch64
    perl-tests-5.16.3-299.amzn2.0.1.aarch64
    perl-Time-Piece-1.20.1-299.amzn2.0.1.aarch64
    perl-core-5.16.3-299.amzn2.0.1.aarch64
    perl-debuginfo-5.16.3-299.amzn2.0.1.aarch64

i686:
    perl-5.16.3-299.amzn2.0.1.i686
    perl-libs-5.16.3-299.amzn2.0.1.i686
    perl-devel-5.16.3-299.amzn2.0.1.i686
    perl-macros-5.16.3-299.amzn2.0.1.i686
    perl-tests-5.16.3-299.amzn2.0.1.i686
    perl-Time-Piece-1.20.1-299.amzn2.0.1.i686
    perl-core-5.16.3-299.amzn2.0.1.i686
    perl-debuginfo-5.16.3-299.amzn2.0.1.i686

noarch:
    perl-CPAN-1.9800-299.amzn2.0.1.noarch
    perl-ExtUtils-CBuilder-0.28.2.6-299.amzn2.0.1.noarch
    perl-ExtUtils-Embed-1.30-299.amzn2.0.1.noarch
    perl-ExtUtils-Install-1.58-299.amzn2.0.1.noarch
    perl-IO-Zlib-1.10-299.amzn2.0.1.noarch
    perl-Locale-Maketext-Simple-0.21-299.amzn2.0.1.noarch
    perl-Module-CoreList-2.76.02-299.amzn2.0.1.noarch
    perl-Module-Loaded-0.08-299.amzn2.0.1.noarch
    perl-Object-Accessor-0.42-299.amzn2.0.1.noarch
    perl-Package-Constants-0.02-299.amzn2.0.1.noarch
    perl-Pod-Escapes-1.04-299.amzn2.0.1.noarch

src:
    perl-5.16.3-299.amzn2.0.1.src

x86_64:
    perl-5.16.3-299.amzn2.0.1.x86_64
    perl-libs-5.16.3-299.amzn2.0.1.x86_64
    perl-devel-5.16.3-299.amzn2.0.1.x86_64
    perl-macros-5.16.3-299.amzn2.0.1.x86_64
    perl-tests-5.16.3-299.amzn2.0.1.x86_64
    perl-Time-Piece-1.20.1-299.amzn2.0.1.x86_64
    perl-core-5.16.3-299.amzn2.0.1.x86_64
    perl-debuginfo-5.16.3-299.amzn2.0.1.x86_64