CVE-2012-5195
published 2012-12-18CVE-2012-5195: Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 allows…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.88%
91.1th percentile
Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 allows context-dependent attackers to cause a denial of service (memory consumption and crash) or possibly execute arbitrary code via the 'x' string repeat operator.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.14.2-14 (bookworm) | perl 5.14.2-14 (bookworm) |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | >= 0 < 5.14.2-14 | 5.14.2-14 |
| perl | perl | >= 0 < 5.14.2-14 | 5.14.2-14 |
| perl | perl | >= 0 < 5.14.2-14 | 5.14.2-14 |
| perl | perl | >= 0 < 5.14.2-14 | 5.14.2-14 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 5.1
CVE-2011-2939 [MEDIUM] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Perl programs could be made to crash or run programs if they receive
specially crafted network traffic or other input.
It was discovered that the decode_xs function in the Encode module is
vulnerable to a heap-based buffer overflow via a crafted Unicode string.
An attacker could use this overflow to cause a denial of service.
(CVE-2011-2939)
It was discovered that the 'new' constructor in the Digest module is
vulnerable to an eval injection. An attacker could use this to execute
arbitrary code. (CVE-2011-3597)
It was discovered that Perl's 'x' string repeat operator is vulnerable
to a heap-based buffer overflow. An attacker could use this to execute
arbitrary code. (CVE-2012-5195)
Ryo Anazawa discovered that the CGI.pm module does not properly esca
Red Hat
perl: heap buffer overrun flaw may lead to arbitrary code execution
vendor_redhat·2012-10-10·CVSS 7.5
CVE-2012-5195 [HIGH] perl: heap buffer overrun flaw may lead to arbitrary code execution
perl: heap buffer overrun flaw may lead to arbitrary code execution
Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 allows context-dependent attackers to cause a denial of service (memory consumption and crash) or possibly execute arbitrary code via the 'x' string repeat operator.
Package: perl (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2012-5195: perl - Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12...
vendor_debian·2012·CVSS 7.5
CVE-2012-5195 [HIGH] CVE-2012-5195: perl - Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12...
Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 allows context-dependent attackers to cause a denial of service (memory consumption and crash) or possibly execute arbitrary code via the 'x' string repeat operator.
Scope: local
bookworm: resolved (fixed in 5.14.2-14)
bullseye: resolved (fixed in 5.14.2-14)
forky: resolved (fixed in 5.14.2-14)
sid: resolved (fixed in 5.14.2-14)
trixie: resolved (fixed in 5.14.2-14)
GHSA
GHSA-6768-qw7m-q528: Heap-based buffer overflow in the Perl_repeatcpy function in util
ghsa_unreviewed·2022-05-17
CVE-2012-5195 [HIGH] CWE-119 GHSA-6768-qw7m-q528: Heap-based buffer overflow in the Perl_repeatcpy function in util
Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 allows context-dependent attackers to cause a denial of service (memory consumption and crash) or possibly execute arbitrary code via the 'x' string repeat operator.
OSV
CVE-2012-5195: Heap-based buffer overflow in the Perl_repeatcpy function in util
osv·2012-12-18·CVSS 7.5
CVE-2012-5195 [HIGH] CVE-2012-5195: Heap-based buffer overflow in the Perl_repeatcpy function in util
Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 allows context-dependent attackers to cause a denial of service (memory consumption and crash) or possibly execute arbitrary code via the 'x' string repeat operator.
No public exploits indexed.
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://perl5.git.perl.org/perl.git/commit/2709980d5a193ce6f3a16f0d19879a6560dcde44http://rhn.redhat.com/errata/RHSA-2013-0685.htmlhttp://secunia.com/advisories/51457http://secunia.com/advisories/55314http://www.debian.org/security/2012/dsa-2586http://www.mandriva.com/security/advisories?name=MDVSA-2013:113http://www.nntp.perl.org/group/perl.perl5.porters/2012/10/msg193886.htmlhttp://www.openwall.com/lists/oss-security/2012/10/26/2http://www.openwall.com/lists/oss-security/2012/10/27/1http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/56287http://www.ubuntu.com/usn/USN-1643-1https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0352http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://perl5.git.perl.org/perl.git/commit/2709980d5a193ce6f3a16f0d19879a6560dcde44http://rhn.redhat.com/errata/RHSA-2013-0685.htmlhttp://secunia.com/advisories/51457http://secunia.com/advisories/55314http://www.debian.org/security/2012/dsa-2586http://www.mandriva.com/security/advisories?name=MDVSA-2013:113http://www.nntp.perl.org/group/perl.perl5.porters/2012/10/msg193886.htmlhttp://www.openwall.com/lists/oss-security/2012/10/26/2http://www.openwall.com/lists/oss-security/2012/10/27/1http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/56287http://www.ubuntu.com/usn/USN-1643-1https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0352
2012-12-18
Published