Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Perl Unicode '\Q...\E' Quoting Construct Regular Expression Buffer Overflow Vulnerability

Perl is prone to a buffer-overflow vulnerability because it fails to sufficiently bounds-check user-supplied input.

Successfully exploiting this issue may allow attackers to execute arbitrary machine code in the context of Perl applications using regular expressions in a vulnerable manner. This facilitates the remote compromise of affected computers. Failed exploits can cause denial-of-service conditions.

Perl 5.8.8 is vulnerable to this issue; other versions may also be affected.

NOTE: This issue may be related to BID 26350 ('Perl Unicode Regular Expression Buffer Overflow Vulnerability').







 

Privacy Statement
Copyright 2008, SecurityFocus