PT-2013-1341 · Perl+4 · Perl+4

Yves Orton

·

Publicado

2013-03-12

·

Atualizado

2024-06-15

·

CVE-2013-1667

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Perl versions 5.8.2 through 5.16.x
Description The issue is related to the rehash mechanism in Perl, which is associated with resource management errors. It allows remote attackers to cause a denial of service, resulting in memory consumption and a crash, by using a crafted hash key. This can be exploited by context-dependent attackers.
Recommendations For Perl versions 5.8.2 through 5.16.x, consider disabling the rehash mechanism as a temporary workaround until a patch is available. Restrict access to the hash key functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02638
CESA-2013_0685
CVE-2013-1667
DSA-2641-1
HPSBUX02928
OPENSUSE-SU-2013_0497-1
OPENSUSE-SU-2013_0502-1
OPENSUSE-SU-2024:10161-1
RHSA-2013:0685
RHSA-2013_0685
SUSE-SU-2013_0441-1
SUSE-SU-2013_0442-1

Produtos afetados

Centos
Hp-Ux
Perl
Red Hat
Suse