7.8
CVSSv2

CVE-2015-7686

Published: 06/10/2015 Updated: 04/07/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and previous versions for Perl allows remote malicious users to cause a denial of service (CPU consumption) via a crafted string containing a list of e-mail addresses in conjunction with parenthesis characters that can be associated with nested comments. NOTE: the default configuration in 1.908 mitigates this vulnerability but misparses certain realistic comments.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

email-address project email-address

Vendor Advisories

Debian Bug report logs - #901873 CVE-2018-12558: DOS vulnerability in perl module Email::Address Package: libemail-address-perl; Maintainer for libemail-address-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libemail-address-perl is src:libemail-address-perl (PTS, buildd, popcon) Reporte ...
Debian Bug report logs - #868170 libemail-address-perl: Email::Address->parse() is vulnerable to CVE-2015-7686 Package: libemail-address-perl; Maintainer for libemail-address-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libemail-address-perl is src:libemail-address-perl (PTS, buildd, popcon ...
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-6127 It was discovered that Request Tracker is vulnerable to a cross-site scripting (XSS) attack if an attacker uploads a malicious file ...
Algorithmic complexity vulnerability in Addresspm in the Email-Address module 1908 and earlier for Perl allows remote attackers to cause a denial of service (CPU consumption) via a crafted string containing a list of e-mail addresses in conjunction with parenthesis characters that can be associated with nested comments NOTE: the default configur ...