Heap-Based Buffer Overflow in Perl 5 by The Perl Foundation
CVE-2017-12837

7.5HIGH

Key Information:

Vendor
Perl
Status
Vendor
CVE Published:
19 September 2017

Summary

A heap-based buffer overflow vulnerability exists in the S_regatom function within regcomp.c of Perl 5, which can be exploited by remote attackers. By using a specially crafted regular expression containing a '\N{}' escape alongside the case-insensitive modifier, an attacker can trigger an out-of-bounds write. This results in a denial of service, potentially compromising the stability and availability of applications utilizing affected versions of Perl.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-12837 : Heap-Based Buffer Overflow in Perl 5 by The Perl Foundation | SecurityVulnerability.io