cbcvebase.
CVE-2018-18314
published 2018-12-07

CVE-2018-18314: Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

Affected

20 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianperl< perl 5.28.0-3 (bookworm)perl 5.28.0-3 (bookworm)
netappe-series_santricity_os_controller11.0 – 11.40
perlperl< 5.26.35.26.3
perlperl>= 0 < 5.28.0-35.28.0-3
perlperl>= 0 < 5.28.0-35.28.0-3
perlperl>= 0 < 5.28.0-35.28.0-3
perlperl>= 0 < 5.28.0-35.28.0-3
perlperl>= 0 < 5.18.2-2ubuntu1.75.18.2-2ubuntu1.7
perlperl>= 0 < 5.22.1-9ubuntu0.65.22.1-9ubuntu0.6
perlperl>= 0 < 5.26.1-6ubuntu0.35.26.1-6ubuntu0.3
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL