CVE-2017-12837
published 2017-09-19CVE-2017-12837: Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.21%
92.7th percentile
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra_10.13.2_security_update_2017-002_sierra_and_security_update_20 | — | — |
| debian | perl | < perl 5.26.0-8 (bookworm) | perl 5.26.0-8 (bookworm) |
| perl | perl | <= 5.24.2 | — |
| perl | perl | — | — |
| perl | perl | >= 0 < 5.26.0-8 | 5.26.0-8 |
| perl | perl | >= 0 < 5.26.0-8 | 5.26.0-8 |
| perl | perl | >= 0 < 5.26.0-8 | 5.26.0-8 |
| perl | perl | >= 0 < 5.26.0-8 | 5.26.0-8 |
| perl | perl | >= 0 < 5.18.2-2ubuntu1.3 | 5.18.2-2ubuntu1.3 |
| perl | perl | >= 0 < 5.22.1-9ubuntu0.2 | 5.22.1-9ubuntu0.2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q52c-c9hv-jc77: Heap-based buffer overflow in the S_regatom function in regcomp
ghsa_unreviewed·2022-05-13
CVE-2017-12837 [HIGH] CWE-119 GHSA-q52c-c9hv-jc77: Heap-based buffer overflow in the S_regatom function in regcomp
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
OSV
perl vulnerabilities
osv·2017-11-13·CVSS 7.5
CVE-2017-12837 [HIGH] perl vulnerabilities
perl vulnerabilities
Jakub Wilk discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-12837, CVE-2017-12883)
OSV
CVE-2017-12837: Heap-based buffer overflow in the S_regatom function in regcomp
osv·2017-09-19·CVSS 7.5
CVE-2017-12837 [HIGH] CVE-2017-12837: Heap-based buffer overflow in the S_regatom function in regcomp
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
Apple
CVE-2017-12837: macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan
vendor_apple·2017-12-06·CVSS 7.5
CVE-2017-12837 [HIGH] CVE-2017-12837: macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan
Product: macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan
CVE: CVE-2017-12837
Component: Perl
Impact: This bugs can allow remote attackers to cause a denial of service
Description: Public CVE-2017-12837 was addressed by updating the function in Perl 5.18
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2017-11-13·CVSS 7.5
CVE-2017-12837 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Perl could be made to crash if it received specially crafted
input.
Jakub Wilk discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-12837, CVE-2017-12883)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl: Heap buffer overflow in regular expression compiler
vendor_redhat·2017-09-12·CVSS 7.5
CVE-2017-12837 [HIGH] CWE-122 perl: Heap buffer overflow in regular expression compiler
perl: Heap buffer overflow in regular expression compiler
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
A heap write buffer overflow was found in perl's S_regatom() function, which is used in the compilation of regular expressions, resulting in the crash of the perl interpreter. An attacker, able to provide a specially crafted regular expression, could cause a denial of service.
Statement: This issue does not affect perl versions older than 5.18. Perl as shipped in Red Hat Enterprise Linux 7 and older are not affected by this vulnerability.
Package: perl (R
Debian
CVE-2017-12837: perl - Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 befo...
vendor_debian·2017·CVSS 7.5
CVE-2017-12837 [HIGH] CVE-2017-12837: perl - Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 befo...
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
Scope: local
bookworm: resolved (fixed in 5.26.0-8)
bullseye: resolved (fixed in 5.26.0-8)
forky: resolved (fixed in 5.26.0-8)
sid: resolved (fixed in 5.26.0-8)
trixie: resolved (fixed in 5.26.0-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12837 perl: Heap buffer overflow in regular expression compiler
bugzilla·2017-09-15·CVSS 7.5
CVE-2017-12837 [HIGH] CVE-2017-12837 perl: Heap buffer overflow in regular expression compiler
CVE-2017-12837 perl: Heap buffer overflow in regular expression compiler
Compiling certain regular expression patterns with the case-insensitive modifier could cause a heap buffer overflow and crash perl.
Upstream patch:
https://perl5.git.perl.org/perl.git/commitdiff/96c83ed78aeea1a0496dd2b2d935869a822dc8a5
Bug report :
https://rt.perl.org/Public/Bug/Display.html?id=131582
Discussion:
Created perl tracking bugs for this issue:
Affects: fedora-all [bug 1492094]
---
Statement:
This issue does not affect perl versions older than 5.18. Perl as shipped in Red Hat Enterprise Linux 7 and older are not affected by this vulnerability.
---
Acknowledgments:
Name: Sawyer X (Perl)
---
perl-5.26.1-401.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, ple
Bugzilla
CVE-2017-12837 CVE-2017-12883 perl: various flaws [fedora-all]
bugzilla·2017-09-15·CVSS 7.5
CVE-2017-12837 [HIGH] CVE-2017-12837 CVE-2017-12883 perl: various flaws [fedora-all]
CVE-2017-12837 CVE-2017-12883 perl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
http://www.debian.org/security/2017/dsa-3982http://www.securityfocus.com/bid/100860https://bugzilla.redhat.com/show_bug.cgi?id=1492091https://perl5.git.perl.org/perl.git/commitdiff/96c83ed78aeea1a0496dd2b2d935869a822dc8a5https://perl5.git.perl.org/perl.git/log/refs/tags/v5.24.3-RC1https://perl5.git.perl.org/perl.git/log/refs/tags/v5.26.1-RC1https://rt.perl.org/Public/Bug/Display.html?id=131582https://security.netapp.com/advisory/ntap-20180426-0001/https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://www.debian.org/security/2017/dsa-3982http://www.securityfocus.com/bid/100860https://bugzilla.redhat.com/show_bug.cgi?id=1492091https://perl5.git.perl.org/perl.git/commitdiff/96c83ed78aeea1a0496dd2b2d935869a822dc8a5https://perl5.git.perl.org/perl.git/log/refs/tags/v5.24.3-RC1https://perl5.git.perl.org/perl.git/log/refs/tags/v5.26.1-RC1https://rt.perl.org/Public/Bug/Display.html?id=131582https://security.netapp.com/advisory/ntap-20180426-0001/https://www.oracle.com/security-alerts/cpujul2020.html
2017-09-19
Published