PT-2012-1219 · Perl+1 · Perl+2

Petr Pisar

+1

·

Published

2011-11-03

·

Updated

2023-02-13

·

CVE-2011-2939

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Encode module versions prior to 2.44 Perl versions prior to 5.15.6
Description The issue is related to an off-by-one error in the decode xs function, which can lead to a denial of service due to memory corruption. This is caused by a heap-based buffer overflow when processing a crafted Unicode string. The vulnerability is associated with errors in number processing and can be exploited by a remote attacker to cause a denial of service.
Recommendations For Encode module versions prior to 2.44, update to version 2.44 or later. For Perl versions prior to 5.15.6, update to version 5.15.6 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2022-02611
CVE-2011-2939
RHSA-2011:1424
RHSA-2011_1424

Affected Products

Encode
Perl
Red Hat