PT-2023-7351 · Perl+3 · Perl+3
CVE-2023-47100
·
Publicado
2023-12-02
·
Atualizado
2025-06-30
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Perl versions 5.30.0 through 5.38.1
Description
The issue is related to the S parse uniprop string function in regcomp.c, which can write to unallocated space due to mishandling of a property name associated with a regular expression construct. This can allow a remote attacker to bypass security restrictions and potentially impact the confidentiality, integrity, and availability of protected information. The vulnerability can be exploited by using a specially crafted regular expression input.
Recommendations
For Perl versions 5.30.0 through 5.38.1, update to version 5.38.2 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the
S parse uniprop string function in regcomp.c until a patch is available.
Avoid using specially crafted regular expression inputs that could exploit this vulnerability until the issue is resolved.Correção
Buffer Overflow
Improper Handling of Exceptional Conditions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibm Aix
Apple Macos
Perl
Red Os