Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape.
CVSS Details
- CVSS 3.0 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl | Oct 25, 2017 | Sep 19, 2017 |
| Debian | — | Upgrade perl | Dec 5, 2017 | Sep 19, 2017 |
| Freebsd | — | Upgrade perl5 | Dec 10, 2025 | Sep 24, 2017 |
| Oracle Solaris | — | Upgrade runtime/perl-522 to version 5.22.1.1-0.175.3.32.0.3.0 on Solaris 11.3 | May 16, 2018 | Sep 19, 2017 |
| Suse | — | Upgrade perl-baseUpgrade perl-base-32bitUpgrade perlUpgrade perl-core-DB_FileUpgrade perl-32bitUpgrade perl-doc | Nov 27, 2017 | Sep 19, 2017 |
| Ubuntu | — | Upgrade perl | Nov 13, 2017 | Sep 19, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub