PT-2013-1341 · Perl+4 · Perl+4

Yves Orton

·

Published

2013-03-12

·

Updated

2024-06-15

·

CVE-2013-1667

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Perl versions 5.8.2 through 5.16.x
Description The issue is related to the rehash mechanism in Perl, which is associated with resource management errors. It allows remote attackers to cause a denial of service, resulting in memory consumption and a crash, by using a crafted hash key. This can be exploited by context-dependent attackers.
Recommendations For Perl versions 5.8.2 through 5.16.x, consider disabling the rehash mechanism as a temporary workaround until a patch is available. Restrict access to the hash key functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02638
CESA-2013_0685
CVE-2013-1667
DSA-2641-1
HPSBUX02928
OPENSUSE-SU-2013_0497-1
OPENSUSE-SU-2013_0502-1
OPENSUSE-SU-2024:10161-1
RHSA-2013:0685
RHSA-2013_0685
SUSE-SU-2013_0441-1
SUSE-SU-2013_0442-1

Affected Products

Centos
Hp-Ux
Perl
Red Hat
Suse