9.1
CVSSv3

CVE-2018-18313

Published: 07/12/2018 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 571
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

Perl prior to 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

perl perl

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

debian debian linux 9.0

redhat enterprise linux 7.4

redhat enterprise linux 7.0

redhat enterprise linux 6.0

redhat enterprise linux 7.5

redhat enterprise linux 7.6

netapp e-series santricity os controller

netapp snap creator framework -

netapp snapdrive -

netapp snapcenter -

apple mac os x

Vendor Advisories

Synopsis Important: rh-perl526-perl security and enhancement update Type/Severity Security Advisory: Important Topic An update for rh-perl526-perl and rh-perl526-perl-Module-CoreList is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact ...
Synopsis Important: rh-perl524-perl security update Type/Severity Security Advisory: Important Topic An update for rh-perl524-perl is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System ...
Several security issues were fixed in Perl ...
Several security issues were fixed in Perl ...
Multiple vulnerabilities were discovered in the implementation of the Perl programming language The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2018-18311 Jayakrishna Menon and Christophe Hauser discovered an integer overflow vulnerability in Perl_my_setenv leading to a heap-based buffer overflo ...
Perl before 5263 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory ...