CVE-2011-2939
published 2012-01-13CVE-2011-2939: Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent…
PriorityP425medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
2.65%
84.1th percentile
Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.
Affected
163 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dan_kogai | encode_module | <= 2.43 | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
| dan_kogai | encode_module | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1LOW
vendor_redhat5.1MEDIUM
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 5.1
CVE-2011-2939 [MEDIUM] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Perl programs could be made to crash or run programs if they receive
specially crafted network traffic or other input.
It was discovered that the decode_xs function in the Encode module is
vulnerable to a heap-based buffer overflow via a crafted Unicode string.
An attacker could use this overflow to cause a denial of service.
(CVE-2011-2939)
It was discovered that the 'new' constructor in the Digest module is
vulnerable to an eval injection. An attacker could use this to execute
arbitrary code. (CVE-2011-3597)
It was discovered that Perl's 'x' string repeat operator is vulnerable
to a heap-based buffer overflow. An attacker could use this to execute
arbitrary code. (CVE-2012-5195)
Ryo Anazawa discovered that the CGI.pm module does not properly esca
Red Hat
Perl decode_xs heap-based buffer overflow
vendor_redhat·2011-08-09·CVSS 5.1
CVE-2011-2939 [MEDIUM] CWE-122 Perl decode_xs heap-based buffer overflow
Perl decode_xs heap-based buffer overflow
Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.
Package: perl (Red Hat Enterprise Linux 4) - Affected
Package: perl (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2011-2939: libencode-perl - Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode m...
vendor_debian·2011·CVSS 5.1
CVE-2011-2939 [MEDIUM] CVE-2011-2939: libencode-perl - Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode m...
Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.44-1)
bullseye: resolved (fixed in 2.44-1)
forky: resolved (fixed in 2.44-1)
sid: resolved (fixed in 2.44-1)
trixie: resolved (fixed in 2.44-1)
GHSA
GHSA-76hr-qp66-cq6j: Off-by-one error in the decode_xs function in Unicode/Unicode
ghsa_unreviewed·2022-05-14
CVE-2011-2939 [MEDIUM] GHSA-76hr-qp66-cq6j: Off-by-one error in the decode_xs function in Unicode/Unicode
Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.
OSV
CVE-2011-2939: Off-by-one error in the decode_xs function in Unicode/Unicode
osv·2012-01-13·CVSS 5.1
CVE-2011-2939 [MEDIUM] CVE-2011-2939: Off-by-one error in the decode_xs function in Unicode/Unicode
Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2939 Perl decode_xs heap-based buffer overflow [fedora-all]
bugzilla·2011-10-04·CVSS 5.1
CVE-2011-2939 [MEDIUM] CVE-2011-2939 Perl decode_xs heap-based buffer overflow [fedora-all]
CVE-2011-2939 Perl decode_xs heap-based buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=731246
Please note: this issue affects multiple suppo
Bugzilla
CVE-2011-2939 Perl decode_xs heap-based buffer overflow
bugzilla·2011-08-17·CVSS 5.1
CVE-2011-2939 [MEDIUM] CVE-2011-2939 Perl decode_xs heap-based buffer overflow
CVE-2011-2939 Perl decode_xs heap-based buffer overflow
Perl bundles `Encode' module (http://search.cpan.org/~dankogai/Encode/) that contains `Unicode.xs' file where a heap overflow bug has been fixed recently (http://cpansearch.perl.org/src/DANKOGAI/Encode-2.44/Changes):
$Revision: 2.44 $ $Date: 2011/08/09 07:49:44 $
! Unicode/Unicode.xs
Addressed the following:
Date: Fri, 22 Jul 2011 13:58:43 +0200
From: Robert Zacek
To: [email protected]
Subject: Unicode.xs!decode_xs n-byte heap-overflow
The patch has been merged into perl development tree (http://perl5.git.perl.org/perl.git/commitdiff/e46d973584785af1f445c4dedbee4243419cb860#patch5):
diff --git a/cpan/Encode/Unicode/Unicode.xs b/cpan/Encode/Unicode/Unicode.xs
index 16f4cd1..039f155 100644 (file)
--- a/cpan/Encode/U
http://cpansearch.perl.org/src/FLORA/perl-5.14.2/pod/perldelta.podhttp://perl5.git.perl.org/perl.git/commitdiff/e46d973584785af1f445c4dedbee4243419cb860#patch5http://search.cpan.org/~flora/perl-5.14.2/pod/perldelta.pod#Encode_decode_xs_n-byte_heap-overflow_%28CVE-2011-2939%29http://secunia.com/advisories/46172http://secunia.com/advisories/46989http://secunia.com/advisories/51457http://secunia.com/advisories/55314http://www.mandriva.com/security/advisories?name=MDVSA-2012:008http://www.openwall.com/lists/oss-security/2011/08/18/8http://www.openwall.com/lists/oss-security/2011/08/19/17http://www.redhat.com/support/errata/RHSA-2011-1424.htmlhttp://www.securityfocus.com/bid/49858http://www.ubuntu.com/usn/USN-1643-1https://bugzilla.redhat.com/show_bug.cgi?id=731246http://cpansearch.perl.org/src/FLORA/perl-5.14.2/pod/perldelta.podhttp://perl5.git.perl.org/perl.git/commitdiff/e46d973584785af1f445c4dedbee4243419cb860#patch5http://search.cpan.org/~flora/perl-5.14.2/pod/perldelta.pod#Encode_decode_xs_n-byte_heap-overflow_%28CVE-2011-2939%29http://secunia.com/advisories/46172http://secunia.com/advisories/46989http://secunia.com/advisories/51457http://secunia.com/advisories/55314http://www.mandriva.com/security/advisories?name=MDVSA-2012:008http://www.openwall.com/lists/oss-security/2011/08/18/8http://www.openwall.com/lists/oss-security/2011/08/19/17http://www.redhat.com/support/errata/RHSA-2011-1424.htmlhttp://www.securityfocus.com/bid/49858http://www.ubuntu.com/usn/USN-1643-1https://bugzilla.redhat.com/show_bug.cgi?id=731246
2012-01-13
Published