CVE-2018-18311
published 2018-12-07CVE-2018-18311: Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
PriorityP353critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
11.68%
95.6th percentile
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.14.4 | 10.14.4 |
| apple | macos_mojave_10.14.4_security_update_2019-002_high_sierra_security_update_2019-0 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | perl | < perl 5.28.1-1 (bookworm) | perl 5.28.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| mcafee | web_gateway | >= 7.7.2 < 7.7.2.21 | 7.7.2.21 |
| mcafee | web_gateway | >= 7.8.2 < 7.8.2.8 | 7.8.2.8 |
| mcafee | web_gateway | >= 8.0.0 < 8.1.1 | 8.1.1 |
| perl | perl | < 5.26.3 | 5.26.3 |
| perl | perl | >= 0 < 5.28.1-1 | 5.28.1-1 |
| perl | perl | >= 0 < 5.28.1-1 | 5.28.1-1 |
| perl | perl | >= 0 < 5.28.1-1 | 5.28.1-1 |
| perl | perl | >= 0 < 5.28.1-1 | 5.28.1-1 |
| perl | perl | >= 0 < 5.18.2-2ubuntu1.7 | 5.18.2-2ubuntu1.7 |
| perl | perl | >= 0 < 5.22.1-9ubuntu0.6 | 5.22.1-9ubuntu0.6 |
| perl | perl | >= 0 < 5.26.1-6ubuntu0.3 | 5.26.1-6ubuntu0.3 |
| perl | perl | >= 5.28.0 < 5.28.1 | 5.28.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_oracle8.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Install (Perl) — CVE-2018-18311
vendor_oracle·2020-04-15·CVSS 8.1
CVE-2018-18311 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Install (Perl) — CVE-2018-18311
Oracle Oracle Enterprise Manager Risk Matrix: Install (Perl) vulnerability
CVE: CVE-2018-18311
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Apple
CVE-2018-18311: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
vendor_apple·2019-03-25·CVSS 9.8
CVE-2018-18311 [CRITICAL] CVE-2018-18311: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
Product: macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra
CVE: CVE-2018-18311
Component: Perl
Impact: Multiple issues in Perl
Description: Multiple issues in Perl were addressed in this update.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2018-12-03·CVSS 9.8
CVE-2018-18311 [CRITICAL] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
Jayakrishna Menon discovered that Perl incorrectly handled Perl_my_setenv.
An attacker could use this issue to cause Perl to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2018-18311)
Eiichi Tsukata discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10.
(CVE-2018-18312)
Eiichi Tsukata discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service. (CVE-2018-18
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2018-12-03·CVSS 9.8
CVE-2018-18311 [CRITICAL] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
USN-3834-1 fixed a vulnerability in perl. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Jayakrishna Menon discovered that Perl incorrectly handled Perl_my_setenv.
An attacker could use this issue to cause Perl to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2018-18311)
Eiichi Tsukata discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service. (CVE-2018-18313)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl: Integer overflow leading to buffer overflow in Perl_my_setenv()
vendor_redhat·2018-11-29·CVSS 9.8
CVE-2018-18311 [CRITICAL] CWE-190 perl: Integer overflow leading to buffer overflow in Perl_my_setenv()
perl: Integer overflow leading to buffer overflow in Perl_my_setenv()
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
Statement: This vulnerability is present in versions of perl included with Red Hat Virtualization Hypervisor and Management Appliance, however it is not exposed in any meaningful way. Perl is only included in these images as a dependency of components which do not manipulate ENV, and are not exposed to user input. A future update may address this issue.
Package: perl (Red Hat Enterprise Linux 5) - Will not fix
Package: perl (Red Hat Enterprise Linux 6) - Will not fix
Package: perl (Red Hat Enterprise Linux 8) - Not affected
Package: perl:5.24/perl (Red Hat Enterprise Linux 8) -
Debian
CVE-2018-18311: perl - Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted ...
vendor_debian·2018·CVSS 9.8
CVE-2018-18311 [CRITICAL] CVE-2018-18311: perl - Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted ...
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
Scope: local
bookworm: resolved (fixed in 5.28.1-1)
bullseye: resolved (fixed in 5.28.1-1)
forky: resolved (fixed in 5.28.1-1)
sid: resolved (fixed in 5.28.1-1)
trixie: resolved (fixed in 5.28.1-1)
GHSA
GHSA-qr73-9894-ffxf: Perl before 5
ghsa_unreviewed·2022-05-13
CVE-2018-18311 [CRITICAL] CWE-787 GHSA-qr73-9894-ffxf: Perl before 5
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
OSV
CVE-2018-18311: Perl before 5
osv·2018-12-07·CVSS 9.8
CVE-2018-18311 [CRITICAL] CVE-2018-18311: Perl before 5
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
OSV
perl vulnerabilities
osv·2018-12-03·CVSS 9.8
CVE-2018-18311 [CRITICAL] perl vulnerabilities
perl vulnerabilities
Jayakrishna Menon discovered that Perl incorrectly handled Perl_my_setenv.
An attacker could use this issue to cause Perl to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2018-18311)
Eiichi Tsukata discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10.
(CVE-2018-18312)
Eiichi Tsukata discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service. (CVE-2018-18313)
Jakub Wilk discovered that Perl incorrectly handled cer
No detection rules found.
No public exploits indexed.
HackerOne
Container scanning and Dependency scanning report leaked to unauthorized users
hackerone·2019-12-13·CVSS 5.0
[MEDIUM] Container scanning and Dependency scanning report leaked to unauthorized users
Container scanning and Dependency scanning report leaked to unauthorized users
Hi GitLab Security team
### Summary
GitLab makes the container scanning and dependency scanning information available as part of a JSON endpoint for merge requests. These reports are output of the CI job and should only be displayed if the visiting user has access to CI. However, right now GitLab displays the the container scanning and dependency scanning reports regardless of this permission, making it available to whoever has access to the merge request.
For public projects, GitLab allows to restrict CI pipelines to project members only (public pipelines disabled). However, in this case, the merge request widget still renders the scanning reports result, which is the outcome of a CI pipeline.
### Steps to
HackerOne
Integer overflow leading to buffer overflow
hackerone·2019-09-25·CVSS 9.8
[CRITICAL] Integer overflow leading to buffer overflow
Integer overflow leading to buffer overflow
There exists an integer overflow in Perl_my_setenv @ util.c : 2070
2070: void Perl_my_setenv(pTHX_ const char *nam, const char *val) {
...
2166: const int nlen = strlen(nam);
...
2171: vlen = strlen(val);
2172: new_env = (char*)safesysmalloc((nlen + vlen + 2) * sizeof(char));
Here in a 64 bit version of Perl, since the arguments `nam` and `val` are user controlled, the 32 bit integers `nlen` and `vlen` are also under the control of the attacker. Therefore, if `nam` and `val` are two very long strings (for example, 2147483647 bytes long), the addition at line 2172 would result in an integer overflow.
The `new_env` would therefore be a chunk of a size which is smaller than the sum of the lengths of the two input strings.
This `new_env` is subs
Bugzilla
CVE-2018-18311 perl: Integer overflow leading to buffer overflow in Perl_my_setenv() [fedora-all]
bugzilla·2018-11-30·CVSS 9.8
CVE-2018-18311 [CRITICAL] CVE-2018-18311 perl: Integer overflow leading to buffer overflow in Perl_my_setenv() [fedora-all]
CVE-2018-18311 perl: Integer overflow leading to buffer overflow in Perl_my_setenv() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2018-18311 perl: Integer overflow leading to buffer overflow in Perl_my_setenv()
bugzilla·2018-11-05·CVSS 9.8
CVE-2018-18311 [CRITICAL] CVE-2018-18311 perl: Integer overflow leading to buffer overflow in Perl_my_setenv()
CVE-2018-18311 perl: Integer overflow leading to buffer overflow in Perl_my_setenv()
A flaw was found in Perl versions 5.8.0 through 5.28. An Integer overflow leading to buffer overflow in Perl_my_setenv function in util.c
Upstream Patch:
https://github.com/Perl/perl5/commit/34716e2a6ee2af96078d62b065b7785c001194be
Discussion:
Upstream ticket:
https://rt.perl.org/Public/Bug/Display.html?id=133204
---
Acknowledgments:
Name: the Perl project
Upstream: Jayakrishna Menon
---
Created perl tracking bugs for this issue:
Affects: fedora-all [bug 1654918]
---
Statement:
This vulnerability is present in versions of perl included with Red Hat Virtualization Hypervisor and Management Appliance, however it is not exposed in any meaningful way. Perl is only included in these images as a d
http://seclists.org/fulldisclosure/2019/Mar/49http://www.securityfocus.com/bid/106145http://www.securitytracker.com/id/1042181https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0001https://access.redhat.com/errata/RHSA-2019:0010https://access.redhat.com/errata/RHSA-2019:0109https://access.redhat.com/errata/RHSA-2019:1790https://access.redhat.com/errata/RHSA-2019:1942https://access.redhat.com/errata/RHSA-2019:2400https://bugzilla.redhat.com/show_bug.cgi?id=1646730https://github.com/Perl/perl5/commit/34716e2a6ee2af96078d62b065b7785c001194behttps://kc.mcafee.com/corporate/index?page=content&id=SB10278https://lists.debian.org/debian-lts-announce/2018/11/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWQGEB543QN7SSBRKYJM6PSOC3RLYGSM/https://metacpan.org/changes/release/SHAY/perl-5.26.3https://metacpan.org/changes/release/SHAY/perl-5.28.1https://rt.perl.org/Ticket/Display.html?id=133204https://seclists.org/bugtraq/2019/Mar/42https://security.gentoo.org/glsa/201909-01https://security.netapp.com/advisory/ntap-20190221-0003/https://support.apple.com/kb/HT209600https://usn.ubuntu.com/3834-1/https://usn.ubuntu.com/3834-2/https://www.debian.org/security/2018/dsa-4347https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://seclists.org/fulldisclosure/2019/Mar/49http://www.securityfocus.com/bid/106145http://www.securitytracker.com/id/1042181https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0001https://access.redhat.com/errata/RHSA-2019:0010https://access.redhat.com/errata/RHSA-2019:0109https://access.redhat.com/errata/RHSA-2019:1790https://access.redhat.com/errata/RHSA-2019:1942https://access.redhat.com/errata/RHSA-2019:2400https://bugzilla.redhat.com/show_bug.cgi?id=1646730https://github.com/Perl/perl5/commit/34716e2a6ee2af96078d62b065b7785c001194behttps://kc.mcafee.com/corporate/index?page=content&id=SB10278https://lists.debian.org/debian-lts-announce/2018/11/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWQGEB543QN7SSBRKYJM6PSOC3RLYGSM/https://metacpan.org/changes/release/SHAY/perl-5.26.3https://metacpan.org/changes/release/SHAY/perl-5.28.1https://rt.perl.org/Ticket/Display.html?id=133204https://seclists.org/bugtraq/2019/Mar/42https://security.gentoo.org/glsa/201909-01https://security.netapp.com/advisory/ntap-20190221-0003/https://support.apple.com/kb/HT209600https://usn.ubuntu.com/3834-1/https://usn.ubuntu.com/3834-2/https://www.debian.org/security/2018/dsa-4347https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2018-12-07
Published