CVE-2014-1474Inefficient Algorithmic Complexity in Libemail-address-list-perl

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 32.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 17

Description

Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denial of service (CPU consumption) via a string without an address.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

debiandebian/libemail-address-list-perl< libemail-address-list-perl 0.03-1 (bookworm)
NVDbestpractical/rt4.2.0, 4.2.1, 4.2.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wgvf-wh5w-rhm5: Algorithmic complexity vulnerability in Email::Address::List before 02022-05-17
OSV
CVE-2014-1474: Algorithmic complexity vulnerability in Email::Address::List before 02014-07-15

📋Vendor Advisories

1
Debian
CVE-2014-1474: libemail-address-list-perl - Algorithmic complexity vulnerability in Email::Address::List before 0.02, as use...2014

📐Framework References

1
CWE
Inefficient Algorithmic Complexity
CVE-2014-1474 — Inefficient Algorithmic Complexity | cvebase