cbcvebase.
CVE-2018-18311
published 2018-12-07

CVE-2018-18311: Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x< 10.14.410.14.4
applemacos_mojave_10.14.4_security_update_2019-002_high_sierra_security_update_2019-0
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianperl< perl 5.28.1-1 (bookworm)perl 5.28.1-1 (bookworm)
fedoraprojectfedora
mcafeeweb_gateway>= 7.7.2 < 7.7.2.217.7.2.21
mcafeeweb_gateway>= 7.8.2 < 7.8.2.87.8.2.8
mcafeeweb_gateway>= 8.0.0 < 8.1.18.1.1
perlperl< 5.26.35.26.3
perlperl>= 0 < 5.28.1-15.28.1-1
perlperl>= 0 < 5.28.1-15.28.1-1
perlperl>= 0 < 5.28.1-15.28.1-1
perlperl>= 0 < 5.28.1-15.28.1-1
perlperl>= 0 < 5.18.2-2ubuntu1.75.18.2-2ubuntu1.7
perlperl>= 0 < 5.22.1-9ubuntu0.65.22.1-9ubuntu0.6
perlperl>= 0 < 5.26.1-6ubuntu0.35.26.1-6ubuntu0.3
perlperl>= 5.28.0 < 5.28.15.28.1
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL