Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl | Dec 7, 2018 | Dec 5, 2018 |
| Debian | — | Upgrade perl | Nov 30, 2018 | Nov 29, 2018 |
| Gentoo Linux | — | Upgrade dev-lang/perl. | Sep 9, 2019 | Dec 5, 2018 |
| Oracle Solaris | — | Upgrade runtime/perl-522 to version 5.22.1.1-0.175.3.36.0.12.0 on Solaris 11.3Upgrade runtime/perl-522 to version 5.22.1.1-11.4.8.0.1.3.0 on Solaris 11.4 | Apr 17, 2019 | Dec 5, 2018 |
| Suse | — | Upgrade perl-base-32bitUpgrade perl-docUpgrade perlUpgrade perl-core-DB_FileUpgrade perl-baseUpgrade perl-32bit | Dec 23, 2018 | Nov 29, 2018 |
| Ubuntu | — | Upgrade perl | Dec 7, 2018 | Nov 29, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 5, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub