CVE-2018-6797
published 2018-04-17CVE-2018-6797: An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.60%
93.1th percentile
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra_10.13.6_security_update_2018-004_sierra_security_update_2018-0 | — | — |
| apple | macos_mojave_10.14.1_security_update_2018-002_high_sierra_security_update_2018-0 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | perl | < perl 5.26.1-6 (bookworm) | perl 5.26.1-6 (bookworm) |
| perl | perl | >= 0 < 5.26.1-6 | 5.26.1-6 |
| perl | perl | >= 0 < 5.26.1-6 | 5.26.1-6 |
| perl | perl | >= 0 < 5.26.1-6 | 5.26.1-6 |
| perl | perl | >= 0 < 5.26.1-6 | 5.26.1-6 |
| perl | perl | >= 0 < 5.18.2-2ubuntu1.4 | 5.18.2-2ubuntu1.4 |
| perl | perl | >= 0 < 5.22.1-9ubuntu0.3 | 5.22.1-9ubuntu0.3 |
| perl | perl | 5.18 – 5.26 | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-6797: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
vendor_apple·2018-10-30·CVSS 9.8
CVE-2018-6797 [CRITICAL] CVE-2018-6797: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
Product: macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra
CVE: CVE-2018-6797
Component: Perl
Impact: Multiple buffer overflow issues existed in Perl
Description: Multiple issues in Perl were addressed with improved memory handling.
Apple
CVE-2018-6797: macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan
vendor_apple·2018-07-09·CVSS 9.8
CVE-2018-6797 [CRITICAL] CVE-2018-6797: macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan
Product: macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan
CVE: CVE-2018-6797
Component: Perl
Impact: Multiple buffer overflow issues existed in Perl
Description: Multiple issues in Perl were addressed with improved memory handling.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2018-04-16·CVSS 7.5
CVE-2015-8853 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
It was discovered that Perl incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause Perl to
hang, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2015-8853)
It was discovered that Perl incorrectly loaded libraries from the current
working directory. A local attacker could possibly use this issue to
execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6185)
It was discovered that Perl incorrectly handled the rmtree and remove_tree
functions. A local attacker could possibly use this issue to set the mode
on arbitrary files. This issue only affected Ubuntu 14.04 LTS and Ubuntu
16.04 LTS.
Red Hat
perl: heap write overflow in regcomp.c
vendor_redhat·2018-04-14·CVSS 9.8
CVE-2018-6797 [CRITICAL] CWE-787 perl: heap write overflow in regcomp.c
perl: heap write overflow in regcomp.c
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
A heap buffer write overflow, with control over the bytes written, was found in the way regular expressions employing Unicode rules are compiled. An attacker, with the ability to provide a specially crafted regular expression, could crash the perl interpreter, or possibly execute arbitrary code.
Statement: Versions of the perl interpreter older than 5.18 are not vulnerable. As a result, the versions of perl as shipped in Red Hat Enterprise Linux version 7, 6 and 5 are not affected by this vulnerability.
Package: perl (Red Hat Enterprise Linux 5) - Not affected
Package: perl (Red Hat Enterpris
Debian
CVE-2018-6797: perl - An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression ...
vendor_debian·2018·CVSS 9.8
CVE-2018-6797 [CRITICAL] CVE-2018-6797: perl - An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression ...
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
Scope: local
bookworm: resolved (fixed in 5.26.1-6)
bullseye: resolved (fixed in 5.26.1-6)
forky: resolved (fixed in 5.26.1-6)
sid: resolved (fixed in 5.26.1-6)
trixie: resolved (fixed in 5.26.1-6)
GHSA
GHSA-8qqx-9gj6-xx9p: An issue was discovered in Perl 5
ghsa_unreviewed·2022-05-13
CVE-2018-6797 [CRITICAL] CWE-787 GHSA-8qqx-9gj6-xx9p: An issue was discovered in Perl 5
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
OSV
CVE-2018-6797: An issue was discovered in Perl 5
osv·2018-04-17·CVSS 9.8
CVE-2018-6797 [CRITICAL] CVE-2018-6797: An issue was discovered in Perl 5
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
OSV
perl vulnerabilities
osv·2018-04-16·CVSS 7.5
CVE-2015-8853 [HIGH] perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause Perl to
hang, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2015-8853)
It was discovered that Perl incorrectly loaded libraries from the current
working directory. A local attacker could possibly use this issue to
execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6185)
It was discovered that Perl incorrectly handled the rmtree and remove_tree
functions. A local attacker could possibly use this issue to set the mode
on arbitrary files. This issue only affected Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2017-6512)
Brian Carpenter discovered that Perl incorre
No detection rules found.
No public exploits indexed.
HackerOne
Heap-buffer-overflow in Perl__byte_dump_string (utf8.c) could lead to memory leak
hackerone·2019-10-24·CVSS 9.8
CVE-2018-6797 [CRITICAL] Heap-buffer-overflow in Perl__byte_dump_string (utf8.c) could lead to memory leak
Heap-buffer-overflow in Perl__byte_dump_string (utf8.c) could lead to memory leak
With crafted regex match, I have found a heap-over-flow in function Perl__byte_dump_string, which would lead to memory leak.
* Reported to the [Perl security mailing list](https://rt.perl.org/Public/Bug/Display.html?id=132063) on 11 Sep 2017.
* Confirmed as a security flaw by TonyC on 24 Feb 2018
* CVE-2018-6797 assigned to this flaw on 7 Feb 2018
* [Public security advisory](https://github.com/Perl/perl5/blob/blead/pod/perl5262delta.pod) released on 14 April 2018
```
==2895==ERROR: AddressSanitizer: heap-buffer-overflow on address 0xb610081c at pc 0x08a72387 bp 0xbfea6038 sp 0xbfea602c
WRITE of size 4 at 0xb610081c thread T0
#0 0x8a72386 in S_pack_rec /root/karas/perl5-blead/pp_pack.c:2703:17
#1 0x8a42706 i
HackerOne
CVE-2018-6797: A crafted regular expression can cause a heap buffer write overflow in Perl 5 giving a remote attacker control over bytes written
hackerone·2018-05-19·CVSS 9.8
CVE-2018-6797 [CRITICAL] CVE-2018-6797: A crafted regular expression can cause a heap buffer write overflow in Perl 5 giving a remote attacker control over bytes written
CVE-2018-6797: A crafted regular expression can cause a heap buffer write overflow in Perl 5 giving a remote attacker control over bytes written
An attacker supplies a regular expression containing one or more `\xDF` characters after an escape putting the regexp into unicode matching mode, such as a `\N{}` escape. Each `\xDF` character adds one byte of overflow, and any other text in the regular expression is written in order, providing the attacker control over the bytes written to the overflowed region.
* Reported to the [Perl security mailing list](https://rt.perl.org/Ticket/Display.html?id=132227) on 6 Oct 2017.
* Confirmed as a security flaw by TonyC on 31 Jan 2018
* CVE-2018-6797 assigned to this flaw on 6 Feb 2018
* Patch released to the security mailing list for Perl 5.24 and Per
Bugzilla
CVE-2018-6797 perl: heap write overflow in regcomp.c [fedora-all]
bugzilla·2018-04-16·CVSS 9.8
CVE-2018-6797 [CRITICAL] CVE-2018-6797 perl: heap write overflow in regcomp.c [fedora-all]
CVE-2018-6797 perl: heap write overflow in regcomp.c [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1547783,1567778
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after update
suggest_re
Bugzilla
CVE-2018-6797 perl: heap write overflow in regcomp.c
bugzilla·2018-02-21·CVSS 9.8
CVE-2018-6797 [CRITICAL] CVE-2018-6797 perl: heap write overflow in regcomp.c
CVE-2018-6797 perl: heap write overflow in regcomp.c
A flaw was found in Perl 5. A heap write overflow in regcomp.c file might be exploited when a perl program allows user input of patterns. A crafted regular expression can cause the heap buffer overflow, with control over the bytes written.
Discussion:
Reproducer:
$ perl -e 'qr/0b\N{U+41}\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xD
http://www.securitytracker.com/id/1040681http://www.securitytracker.com/id/1042004https://access.redhat.com/errata/RHSA-2018:1192https://rt.perl.org/Public/Bug/Display.html?id=132227https://security.gentoo.org/glsa/201909-01https://usn.ubuntu.com/3625-1/https://www.debian.org/security/2018/dsa-4172https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://www.securitytracker.com/id/1040681http://www.securitytracker.com/id/1042004https://access.redhat.com/errata/RHSA-2018:1192https://rt.perl.org/Public/Bug/Display.html?id=132227https://security.gentoo.org/glsa/201909-01https://usn.ubuntu.com/3625-1/https://www.debian.org/security/2018/dsa-4172https://www.oracle.com/security-alerts/cpujul2020.html
2018-04-17
Published