PT-2012-5832 · Perl+2 · Perl+2

Tim Brown

·

Publicado

2012-12-18

·

Atualizado

2016-12-08

·

CVE-2012-5195

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Perl versions 5.12.x through 5.12.4 Perl versions 5.14.x through 5.14.2 Perl versions 5.15.x through 5.15.4
Description The issue is related to a heap-based buffer overflow in the Perl repeatcpy function, which can be exploited by context-dependent attackers. This can lead to a denial of service due to memory consumption and crash, or potentially allow the execution of arbitrary code. The exploitation is possible via the 'x' string repeat operator.
Recommendations For Perl versions 5.12.x through 5.12.4, update to version 5.12.5 or later. For Perl versions 5.14.x through 5.14.2, update to version 5.14.3 or later. For Perl versions 5.15.x through 5.15.4, update to version 5.15.5 or later.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2013_0685
CVE-2012-5195
DSA-2586-1
RHSA-2013:0685
RHSA-2013_0685

Produtos afetados

Centos
Perl
Red Hat