CVE-2008-1927
published 2008-04-24CVE-2008-1927: Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.15%
86.6th percentile
Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular expression containing UTF8 characters. NOTE: this issue might only be present on certain operating systems.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.10.0-1 (bookworm) | perl 5.10.0-1 (bookworm) |
| perl | perl | — | — |
| perl | perl | >= 0 < 5.10.0-1 | 5.10.0-1 |
| perl | perl | >= 0 < 5.10.0-1 | 5.10.0-1 |
| perl | perl | >= 0 < 5.10.0-1 | 5.10.0-1 |
| perl | perl | >= 0 < 5.10.0-1 | 5.10.0-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl regression
vendor_ubuntu·2009-01-15·CVSS 6.8
[MEDIUM] Perl regression
Title: Perl regression
Summary: Perl regression
USN-700-1 fixed vulnerabilities in Perl. Due to problems with the Ubuntu
8.04 build, some Perl .ph files were missing from the resulting update.
This update fixes the problem. We apologize for the inconvenience.
Original advisory details:
Jonathan Smith discovered that the Archive::Tar Perl module did not
correctly handle symlinks when extracting archives. If a user or
automated system were tricked into opening a specially crafted tar file,
a remote attacker could over-write arbitrary files. (CVE-2007-4829)
Tavis Ormandy and Will Drewry discovered that Perl did not correctly
handle certain utf8 characters in regular expressions. If a user or
automated system were tricked into using a specially crafted expression,
a remote attacker could
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2008-12-24·CVSS 6.8
CVE-2007-4829 [MEDIUM] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Perl vulnerabilities
Jonathan Smith discovered that the Archive::Tar Perl module did not
correctly handle symlinks when extracting archives. If a user or
automated system were tricked into opening a specially crafted tar file,
a remote attacker could over-write arbitrary files. (CVE-2007-4829)
Tavis Ormandy and Will Drewry discovered that Perl did not correctly
handle certain utf8 characters in regular expressions. If a user or
automated system were tricked into using a specially crafted expression,
a remote attacker could crash the application, leading to a denial
of service. Ubuntu 8.10 was not affected by this issue. (CVE-2008-1927)
A race condition was discovered in the File::Path Perl module's rmtree
function. If a local attacker successfully r
Debian
CVE-2008-1927: perl - Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to ca...
vendor_debian·2008·CVSS 5.0
CVE-2008-1927 [MEDIUM] CVE-2008-1927: perl - Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to ca...
Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular expression containing UTF8 characters. NOTE: this issue might only be present on certain operating systems.
Scope: local
bookworm: resolved (fixed in 5.10.0-1)
bullseye: resolved (fixed in 5.10.0-1)
forky: resolved (fixed in 5.10.0-1)
sid: resolved (fixed in 5.10.0-1)
trixie: resolved (fixed in 5.10.0-1)
Red Hat
perl: heap corruption by regular expressions with utf8 characters
vendor_redhat·2007-12-04·CVSS 5.0
CVE-2008-1927 [MEDIUM] perl: heap corruption by regular expressions with utf8 characters
perl: heap corruption by regular expressions with utf8 characters
Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular expression containing UTF8 characters. NOTE: this issue might only be present on certain operating systems.
GHSA
GHSA-cjr5-49hf-284r: Double free vulnerability in Perl 5
ghsa_unreviewed·2022-05-01
CVE-2008-1927 [MEDIUM] GHSA-cjr5-49hf-284r: Double free vulnerability in Perl 5
Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular expression containing UTF8 characters. NOTE: this issue might only be present on certain operating systems.
OSV
CVE-2008-1927: Double free vulnerability in Perl 5
osv·2008-04-24·CVSS 5.0
CVE-2008-1927 [MEDIUM] CVE-2008-1927: Double free vulnerability in Perl 5
Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular expression containing UTF8 characters. NOTE: this issue might only be present on certain operating systems.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1927 icedtea-web: GIFAR issue
bugzilla·2012-12-06·CVSS 9.0
CVE-2013-1927 [CRITICAL] CVE-2013-1927 icedtea-web: GIFAR issue
CVE-2013-1927 icedtea-web: GIFAR issue
Current IcedTea-Web versions are affected by GIFAR issue. It is possible to combine GIF image with Java JAR into a single file, that is both valid GIF as well as valid JAR/ZIP file. This issue can be used to execute Java applet in the context of the site that allows untrusted users to upload images in GIF format.
This problem was previously fixed in Oracle and IBM Java plugins as CVE-2008-5343 (bug 474790).
References:
http://en.wikipedia.org/wiki/Gifar
http://xs-sniper.com/blog/2008/12/17/sun-fixes-gifars/
http://riosec.com/how-to-create-a-gifar
Discussion:
Created attachment 659469
proposed patch
This patch is fixing the issue. Troubles will come when not just zip jars will be used (and so jar header will change) - eg pack2000 in jdk8.
Otherwi
Bugzilla
CVE-2008-1927 perl: heap corruption by regular expressions with utf8 characters
bugzilla·2008-04-24·CVSS 5.0
CVE-2008-1927 [MEDIUM] CVE-2008-1927 perl: heap corruption by regular expressions with utf8 characters
CVE-2008-1927 perl: heap corruption by regular expressions with utf8 characters
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1927 to the following vulnerability:
Double free vulnerability in Perl 5.8.8 allows context-dependent
attackers to cause a denial of service (memory corruption and crash)
via a crafted regular expression containing UTF8 characters. NOTE:
this issue might only be present on certain operating systems.
References:
http://rt.perl.org/rt3/Public/Bug/Display.html?id=48156
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=454792
Discussion:
Created attachment 303744
Patch from DSA-1556-1
http://www.debian.org/security/2008/dsa-1556
http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=26;filename=27_fix_regcomp_utf8;att=1;bug=454792
---
Created att
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=454792http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlhttp://osvdb.org/44588http://rt.perl.org/rt3/Public/Bug/Display.html?id=48156http://secunia.com/advisories/29948http://secunia.com/advisories/30025http://secunia.com/advisories/30326http://secunia.com/advisories/30624http://secunia.com/advisories/31208http://secunia.com/advisories/31328http://secunia.com/advisories/31467http://secunia.com/advisories/31604http://secunia.com/advisories/31687http://secunia.com/advisories/33314http://secunia.com/advisories/33937http://support.apple.com/kb/HT3438http://support.avaya.com/elmodocs2/security/ASA-2008-317.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-361.htmhttp://wiki.rpath.com/Advisories:rPSA-2009-0011http://www.debian.org/security/2008/dsa-1556http://www.gentoo.org/security/en/glsa/glsa-200805-17.xmlhttp://www.ipcop.org/index.php?name=News&file=article&sid=41http://www.mandriva.com/security/advisories?name=MDVSA-2008:100http://www.redhat.com/support/errata/RHSA-2008-0522.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0532.htmlhttp://www.securityfocus.com/archive/1/500210/100/0/threadedhttp://www.securityfocus.com/bid/28928http://www.securitytracker.com/id?1020253http://www.ubuntu.com/usn/usn-700-1http://www.ubuntu.com/usn/usn-700-2http://www.vmware.com/security/advisories/VMSA-2008-0013.htmlhttp://www.vupen.com/english/advisories/2008/2265/referenceshttp://www.vupen.com/english/advisories/2008/2361http://www.vupen.com/english/advisories/2008/2424http://www.vupen.com/english/advisories/2009/0422https://exchange.xforce.ibmcloud.com/vulnerabilities/41996https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10579https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00601.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00607.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=454792http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlhttp://osvdb.org/44588http://rt.perl.org/rt3/Public/Bug/Display.html?id=48156http://secunia.com/advisories/29948http://secunia.com/advisories/30025http://secunia.com/advisories/30326http://secunia.com/advisories/30624http://secunia.com/advisories/31208http://secunia.com/advisories/31328http://secunia.com/advisories/31467http://secunia.com/advisories/31604http://secunia.com/advisories/31687http://secunia.com/advisories/33314http://secunia.com/advisories/33937http://support.apple.com/kb/HT3438http://support.avaya.com/elmodocs2/security/ASA-2008-317.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-361.htmhttp://wiki.rpath.com/Advisories:rPSA-2009-0011http://www.debian.org/security/2008/dsa-1556http://www.gentoo.org/security/en/glsa/glsa-200805-17.xmlhttp://www.ipcop.org/index.php?name=News&file=article&sid=41http://www.mandriva.com/security/advisories?name=MDVSA-2008:100http://www.redhat.com/support/errata/RHSA-2008-0522.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0532.htmlhttp://www.securityfocus.com/archive/1/500210/100/0/threadedhttp://www.securityfocus.com/bid/28928http://www.securitytracker.com/id?1020253http://www.ubuntu.com/usn/usn-700-1http://www.ubuntu.com/usn/usn-700-2http://www.vmware.com/security/advisories/VMSA-2008-0013.htmlhttp://www.vupen.com/english/advisories/2008/2265/referenceshttp://www.vupen.com/english/advisories/2008/2361http://www.vupen.com/english/advisories/2008/2424http://www.vupen.com/english/advisories/2009/0422https://exchange.xforce.ibmcloud.com/vulnerabilities/41996https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10579https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00601.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00607.html
2008-04-24
Published