9.8
CVSSv3

CVE-2018-6797

Published: 17/04/2018 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Perl 5.18 up to and including 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 9.0

perl perl

canonical ubuntu linux 16.04

canonical ubuntu linux 17.10

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux workstation 6.0

redhat enterprise linux server 7.4

redhat enterprise linux server 7.3

redhat enterprise linux server 7.5

redhat enterprise linux server 7.6

Vendor Advisories

Synopsis Moderate: rh-perl524-perl security update Type/Severity Security Advisory: Moderate Topic An update for rh-perl524-perl is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CV ...
Several security issues were fixed in Perl ...
Multiple vulnerabilities were discovered in the implementation of the Perl programming language The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2018-6797 Brian Carpenter reported that a crafted regular expression could cause a heap buffer write overflow, with control over the bytes written CVE- ...
A heap buffer write overflow, with control over the bytes written, was found in the way regular expressions employing Unicode rules are compiled An attacker, with the ability to provide a specially crafted regular expression, could crash the perl interpreter, or possibly execute arbitrary code ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-10-30-14 Additional information for APPLE-SA-2018-7-9-4 macOS High Sierra 10136, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan macOS High Sierra 10136, Security Update 2018-004 Sierra, and Security Update 2018-004 El Capitan address the following: AMD Availa ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-10-30-2 macOS Mojave 10141, Security Update 2018-001 High Sierra, Security Update 2018-005 Sierra macOS Mojave 10141, Security Update 2018-001 High Sierra, and Security Update 2018-005 Sierra are now available and address the following: afpserver Available for: macOS Sierra 1012 ...