Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-perl | Oct 25, 2017 | Sep 19, 2017 | |
| Apple Osx Perl | apple-osx-security-update-2017-002-sierra | Oct 3, 2018 | Sep 19, 2017 | |
| Debian | debian-upgrade-perl | Dec 5, 2017 | Sep 19, 2017 | |
| Freebsd | freebsd-upgrade-package-perl5 | Dec 10, 2025 | Sep 24, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-runtime-perl-522-5-22-1-1-0-175-3-32-0-3-0 | May 16, 2018 | Sep 19, 2017 | |
| Suse | — | suse-upgrade-perlsuse-upgrade-perl-32bitsuse-upgrade-perl-basesuse-upgrade-perl-base-32bitsuse-upgrade-perl-core-db_filesuse-upgrade-perl-doc | Nov 27, 2017 | Sep 19, 2017 |
| Ubuntu | ubuntu-upgrade-perl | Nov 13, 2017 | Sep 19, 2017 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Sep 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub