CVE-2013-7422
published 2015-08-16CVE-2013-7422: Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.04%
86.1th percentile
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | perl | < perl 5.20.0-1 (bookworm) | perl 5.20.0-1 (bookworm) |
| perl | perl | — | — |
| perl | perl | >= 0 < 5.20.0-1 | 5.20.0-1 |
| perl | perl | >= 0 < 5.20.0-1 | 5.20.0-1 |
| perl | perl | >= 0 < 5.20.0-1 | 5.20.0-1 |
| perl | perl | >= 0 < 5.20.0-1 | 5.20.0-1 |
| perl | perl | >= 0 < 5.18.2-2ubuntu1.1 | 5.18.2-2ubuntu1.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m7pj-qf68-j4wp: Integer underflow in regcomp
ghsa_unreviewed·2022-05-17
CVE-2013-7422 [HIGH] GHSA-m7pj-qf68-j4wp: Integer underflow in regcomp
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
OSV
perl vulnerabilities
osv·2016-03-02·CVSS 7.5
CVE-2013-7422 [HIGH] perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
OSV
CVE-2013-7422: Integer underflow in regcomp
osv·2015-08-16·CVSS 7.5
CVE-2013-7422 [HIGH] CVE-2013-7422: Integer underflow in regcomp
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2016-03-02·CVSS 7.5
CVE-2013-7422 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
Instructions: In general, a standard system update wil
Red Hat
perl: segmentation fault in S_regmatch on negative backreference
vendor_redhat·2015-01-23·CVSS 7.5
CVE-2013-7422 [HIGH] CWE-190 perl: segmentation fault in S_regmatch on negative backreference
perl: segmentation fault in S_regmatch on negative backreference
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: perl (Red Hat Directory Server 8) - Will not fix
Package: perl (Red Hat Enterprise Linux 5) - Will not fix
Package: p
Debian
CVE-2013-7422: perl - Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before...
vendor_debian·2013·CVSS 7.5
CVE-2013-7422 [HIGH] CVE-2013-7422: perl - Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before...
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
Scope: local
bookworm: resolved (fixed in 5.20.0-1)
bullseye: resolved (fixed in 5.20.0-1)
forky: resolved (fixed in 5.20.0-1)
sid: resolved (fixed in 5.20.0-1)
trixie: resolved (fixed in 5.20.0-1)
Apple
CVE-2013-7422: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 7.5
CVE-2013-7422 [HIGH] CVE-2013-7422: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2013-7422
Component: CVE-2013-7422
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7422 perl: segmentation fault in S_regmatch on negative backreference
bugzilla·2015-01-29·CVSS 7.5
CVE-2013-7422 [HIGH] CVE-2013-7422 perl: segmentation fault in S_regmatch on negative backreference
CVE-2013-7422 perl: segmentation fault in S_regmatch on negative backreference
An integer underflow flaw was discovered in the way Perl parsed regular expression backreferences. An attacker able to supply a crafted regular expression to a Perl application could possibly use this flaw to crash that application.
Reproducer:
$ perl -e '/\7777777777/'
Segmentation fault
Upstream issue:
https://rt.perl.org/Public/Bug/Display.html?id=119505
Upstream patch:
http://perl5.git.perl.org/perl.git/commitdiff/0c2990d652e985784f095bba4bc356481a66aa06
Discussion:
Created perl tracking bugs for this issue:
Affects: fedora-all [bug 1187151]
---
The code responsible for processing regular expression backreferences in regcomp.c did not properly handle large digit strings. An attacker able to pass
Bugzilla
CVE-2013-7422 perl: segmentation fault in S_regmatch on negative backreference [fedora-all]
bugzilla·2015-01-29·CVSS 7.5
CVE-2013-7422 [HIGH] CVE-2013-7422 perl: segmentation fault in S_regmatch on negative backreference [fedora-all]
CVE-2013-7422 perl: segmentation fault in S_regmatch on negative backreference [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://perl5.git.perl.org/perl.git/commit/0c2990d652e985784f095bba4bc356481a66aa06http://www.securityfocus.com/bid/75704http://www.ubuntu.com/usn/USN-2916-1https://security.gentoo.org/glsa/201507-11https://support.apple.com/kb/HT205031http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://perl5.git.perl.org/perl.git/commit/0c2990d652e985784f095bba4bc356481a66aa06http://www.securityfocus.com/bid/75704http://www.ubuntu.com/usn/USN-2916-1https://security.gentoo.org/glsa/201507-11https://support.apple.com/kb/HT205031
2015-08-16
Published