cbcvebase.
CVE-2018-18313
published 2018-12-07

CVE-2018-18313: Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.

critical9.1CVSS 3.0
AVNACLPRNUINSUCHINAH
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.

Affected

23 ranges
VendorProductVersion rangeFixed in
applemac_os_x< 10.14.410.14.4
applemacos_mojave_10.14.4_security_update_2019-002_high_sierra_security_update_2019-0
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianperl< perl 5.28.0-3 (bookworm)perl 5.28.0-3 (bookworm)
netappe-series_santricity_os_controller11.0 – 11.40
perlperl< 5.26.35.26.3
perlperl>= 0 < 5.28.0-35.28.0-3
perlperl>= 0 < 5.28.0-35.28.0-3
perlperl>= 0 < 5.28.0-35.28.0-3
perlperl>= 0 < 5.28.0-35.28.0-3
perlperl>= 0 < 5.18.2-2ubuntu1.75.18.2-2ubuntu1.7
perlperl>= 0 < 5.22.1-9ubuntu0.65.22.1-9ubuntu0.6
perlperl>= 0 < 5.26.1-6ubuntu0.35.26.1-6ubuntu0.3
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.8CRITICAL