CVE-2013-7422Integer Overflow or Wraparound in Perl

Severity
7.5HIGHNVD
EPSS
0.7%
top 26.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16
Latest updateMay 17

Description

Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

debiandebian/perl< perl 5.20.0-1 (bookworm)
Debianperl/perl< 5.20.0-1+3
Ubuntuperl/perl< 5.18.2-2ubuntu1.1
NVDapple/mac_os_x10.10.4
NVDperl/perl5.18.4

🔴Vulnerability Details

3
GHSA
GHSA-m7pj-qf68-j4wp: Integer underflow in regcomp2022-05-17
OSV
perl vulnerabilities2016-03-02
OSV
CVE-2013-7422: Integer underflow in regcomp2015-08-16

📋Vendor Advisories

4
Ubuntu
Perl vulnerabilities2016-03-02
Red Hat
perl: segmentation fault in S_regmatch on negative backreference2015-01-23
Debian
CVE-2013-7422: perl - Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before...2013
Apple
CVE-2013-7422: OS X Yosemite v10.10.5 and Security Update 2015-006

💬Community

2
Bugzilla
CVE-2013-7422 perl: segmentation fault in S_regmatch on negative backreference2015-01-29
Bugzilla
CVE-2013-7422 perl: segmentation fault in S_regmatch on negative backreference [fedora-all]2015-01-29