CVE-2013-1667
published 2013-03-14CVE-2013-1667: The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.45%
87.8th percentile
The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.14.2-19 (bookworm) | perl 5.14.2-19 (bookworm) |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wv37-679q-qgxw: The rehash mechanism in Perl 5
ghsa_unreviewed·2022-05-17
CVE-2013-1667 [HIGH] GHSA-wv37-679q-qgxw: The rehash mechanism in Perl 5
The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.
OSV
CVE-2013-1667: The rehash mechanism in Perl 5
osv·2013-03-14·CVSS 7.5
CVE-2013-1667 [HIGH] CVE-2013-1667: The rehash mechanism in Perl 5
The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.
Ubuntu
Perl vulnerability
vendor_ubuntu·2013-03-19
CVE-2013-1667 Perl vulnerability
Title: Perl vulnerability
Summary: Perl could be made to stop responding if it received specially crafted
input.
Yves Orton discovered that Perl incorrectly handled hashing when using
user-provided hash keys. An attacker could use this flaw to perform a
denial of service attack against software written in Perl.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl: DoS in rehashing code
vendor_redhat·2013-03-04·CVSS 7.5
CVE-2013-1667 [HIGH] perl: DoS in rehashing code
perl: DoS in rehashing code
The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.
Debian
CVE-2013-1667: perl - The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attac...
vendor_debian·2013·CVSS 7.5
CVE-2013-1667 [HIGH] CVE-2013-1667: perl - The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attac...
The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.
Scope: local
bookworm: resolved (fixed in 5.14.2-19)
bullseye: resolved (fixed in 5.14.2-19)
forky: resolved (fixed in 5.14.2-19)
sid: resolved (fixed in 5.14.2-19)
trixie: resolved (fixed in 5.14.2-19)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1667 perl: DoS in rehashing code [fedora-all]
bugzilla·2013-03-05·CVSS 7.5
CVE-2013-1667 [HIGH] CVE-2013-1667 perl: DoS in rehashing code [fedora-all]
CVE-2013-1667 perl: DoS in rehashing code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple supported
Bugzilla
CVE-2013-1667 perl: DoS in rehashing code
bugzilla·2013-02-18·CVSS 7.5
CVE-2013-1667 [HIGH] CVE-2013-1667 perl: DoS in rehashing code
CVE-2013-1667 perl: DoS in rehashing code
A denial of service flaw was found in the way Perl's rehashing code implementation (responsible for recalculation of hash keys and redistribution of hash content) used to react on certain user's input. If a Perl language based application accepted untrusted user input as hash keys, an attacker could use this flaw to cause the perl executable to consume excessive amount of memory (a denial of service via memory exhaustion).
References:
[1] http://www.nntp.perl.org/group/perl.perl5.porters/2013/03/msg199755.html
Discussion:
Created attachment 698789
Proposed upstream patch against perl-5.8.5 version
---
Created attachment 698790
Proposed upstream patch against perl-5.8.8 version
---
Created attachment 698791
Proposed upstream patch against pe
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702296http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.htmlhttp://marc.info/?l=bugtraq&m=137891988921058&w=2http://osvdb.org/90892http://perl5.git.perl.org/perl.git/commitdiff/6e79fe5http://perl5.git.perl.org/perl.git/commitdiff/9d83adchttp://perl5.git.perl.org/perl.git/commitdiff/d59e31fhttp://rhn.redhat.com/errata/RHSA-2013-0685.htmlhttp://secunia.com/advisories/52472http://secunia.com/advisories/52499http://www.debian.org/security/2013/dsa-2641http://www.mandriva.com/security/advisories?name=MDVSA-2013:113http://www.nntp.perl.org/group/perl.perl5.porters/2013/03/msg199755.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/58311http://www.ubuntu.com/usn/USN-1770-1https://bugzilla.redhat.com/show_bug.cgi?id=912276https://exchange.xforce.ibmcloud.com/vulnerabilities/82598https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18771https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0094http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702296http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.htmlhttp://marc.info/?l=bugtraq&m=137891988921058&w=2http://osvdb.org/90892http://perl5.git.perl.org/perl.git/commitdiff/6e79fe5http://perl5.git.perl.org/perl.git/commitdiff/9d83adchttp://perl5.git.perl.org/perl.git/commitdiff/d59e31fhttp://rhn.redhat.com/errata/RHSA-2013-0685.htmlhttp://secunia.com/advisories/52472http://secunia.com/advisories/52499http://www.debian.org/security/2013/dsa-2641http://www.mandriva.com/security/advisories?name=MDVSA-2013:113http://www.nntp.perl.org/group/perl.perl5.porters/2013/03/msg199755.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/58311http://www.ubuntu.com/usn/USN-1770-1https://bugzilla.redhat.com/show_bug.cgi?id=912276https://exchange.xforce.ibmcloud.com/vulnerabilities/82598https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18771https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0094
2013-03-14
Published