PT-2023-7351 · Perl+3 · Perl+3

CVE-2023-47100

·

Publicado

2023-12-02

·

Atualizado

2025-06-30

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Perl versions 5.30.0 through 5.38.1
Description The issue is related to the S parse uniprop string function in regcomp.c, which can write to unallocated space due to mishandling of a property name associated with a regular expression construct. This can allow a remote attacker to bypass security restrictions and potentially impact the confidentiality, integrity, and availability of protected information. The vulnerability can be exploited by using a specially crafted regular expression input.
Recommendations For Perl versions 5.30.0 through 5.38.1, update to version 5.38.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the S parse uniprop string function in regcomp.c until a patch is available. Avoid using specially crafted regular expression inputs that could exploit this vulnerability until the issue is resolved.

Correção

Buffer Overflow

Improper Handling of Exceptional Conditions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08382
CVE-2023-47100
OESA-2023-1926
OESA-2023-1927
OESA-2023-1928
ROSA-SA-2025-2661

Produtos afetados

Ibm Aix
Apple Macos
Perl
Red Os