PT-2023-7351 · Perl+3 · Perl+3
Published
2023-12-02
·
Updated
2025-06-30
·
CVE-2023-47100
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Perl versions 5.30.0 through 5.38.1
Description
The issue is related to the S parse uniprop string function in regcomp.c, which can write to unallocated space due to mishandling of a property name associated with a regular expression construct. This can allow a remote attacker to bypass security restrictions and potentially impact the confidentiality, integrity, and availability of protected information. The vulnerability can be exploited by using a specially crafted regular expression input.
Recommendations
For Perl versions 5.30.0 through 5.38.1, update to version 5.38.2 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the
S parse uniprop string function in regcomp.c until a patch is available.
Avoid using specially crafted regular expression inputs that could exploit this vulnerability until the issue is resolved.Fix
Buffer Overflow
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Aix
Apple Macos
Perl
Red Os