PT-2014-6073 · Perl · Email::Address
Published
2014-07-06
·
Updated
2014-09-26
·
CVE-2014-4720
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Email::Address module versions prior to 1.904
Description
The issue allows remote attackers to cause a denial of service due to CPU consumption. This is achieved through vectors related to backtracking into the phrase, which is caused by an inefficient regular expression used in the Email::Address module.
Recommendations
For versions prior to 1.904, update to version 1.904 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Email::Address