An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
References
Link | Resource |
---|---|
https://www.debian.org/security/2018/dsa-4172 | Third Party Advisory |
https://rt.perl.org/Public/Bug/Display.html?id=132063 | Vendor Advisory |
http://www.securitytracker.com/id/1040681 | Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2018:1192 | Third Party Advisory |
https://usn.ubuntu.com/3625-1/ | Third Party Advisory |
https://security.gentoo.org/glsa/201909-01 | |
https://www.oracle.com/security-alerts/cpujul2020.html |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2018-04-17 13:29
Updated : 2020-07-14 20:15
NVD link : CVE-2018-6798
Mitre link : CVE-2018-6798
JSON object : View
CWE
CWE-125
Out-of-bounds Read
Products Affected
redhat
- enterprise_linux_workstation
- enterprise_linux_server
perl
- perl
canonical
- ubuntu_linux
debian
- debian_linux