Heap-Based Buffer Overflow in Perl 5 by The Perl Foundation
CVE-2017-12837
7.5HIGH
Summary
A heap-based buffer overflow vulnerability exists in the S_regatom function within regcomp.c of Perl 5, which can be exploited by remote attackers. By using a specially crafted regular expression containing a '\N{}' escape alongside the case-insensitive modifier, an attacker can trigger an out-of-bounds write. This results in a denial of service, potentially compromising the stability and availability of applications utilizing affected versions of Perl.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved