|
Perl Unicode '\Q...\E' Quoting Construct Regular Expression Buffer Overflow Vulnerability
Perl is prone to a buffer-overflow vulnerability because it fails to sufficiently bounds-check user-supplied input. Successfully exploiting this issue may allow attackers to execute arbitrary machine code in the context of Perl applications using regular expressions in a vulnerable manner. This facilitates the remote compromise of affected computers. Failed exploits can cause denial-of-service conditions. Perl 5.8.8 is vulnerable to this issue; other versions may also be affected. NOTE: This issue may be related to BID 26350 ('Perl Unicode Regular Expression Buffer Overflow Vulnerability'). |
|
|
Privacy Statement |