CVE-2018-6798
published 2018-04-17CVE-2018-6798: An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
4.00%
89.4th percentile
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | perl | < perl 5.26.1-6 (bookworm) | perl 5.26.1-6 (bookworm) |
| perl | perl | >= 0 < 5.26.1-6 | 5.26.1-6 |
| perl | perl | >= 0 < 5.26.1-6 | 5.26.1-6 |
| perl | perl | >= 0 < 5.26.1-6 | 5.26.1-6 |
| perl | perl | >= 0 < 5.26.1-6 | 5.26.1-6 |
| perl | perl | >= 0 < 5.18.2-2ubuntu1.4 | 5.18.2-2ubuntu1.4 |
| perl | perl | >= 0 < 5.22.1-9ubuntu0.3 | 5.22.1-9ubuntu0.3 |
| perl | perl | 5.22 – 5.26 | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pfh3-76fp-4978: An issue was discovered in Perl 5
ghsa_unreviewed·2022-05-13
CVE-2018-6798 [HIGH] CWE-125 GHSA-pfh3-76fp-4978: An issue was discovered in Perl 5
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
OSV
CVE-2018-6798: An issue was discovered in Perl 5
osv·2018-04-17·CVSS 7.5
CVE-2018-6798 [HIGH] CVE-2018-6798: An issue was discovered in Perl 5
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
OSV
perl vulnerabilities
osv·2018-04-16·CVSS 7.5
CVE-2015-8853 [HIGH] perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause Perl to
hang, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2015-8853)
It was discovered that Perl incorrectly loaded libraries from the current
working directory. A local attacker could possibly use this issue to
execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6185)
It was discovered that Perl incorrectly handled the rmtree and remove_tree
functions. A local attacker could possibly use this issue to set the mode
on arbitrary files. This issue only affected Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2017-6512)
Brian Carpenter discovered that Perl incorre
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2018-04-16·CVSS 7.5
CVE-2015-8853 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
It was discovered that Perl incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause Perl to
hang, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2015-8853)
It was discovered that Perl incorrectly loaded libraries from the current
working directory. A local attacker could possibly use this issue to
execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6185)
It was discovered that Perl incorrectly handled the rmtree and remove_tree
functions. A local attacker could possibly use this issue to set the mode
on arbitrary files. This issue only affected Ubuntu 14.04 LTS and Ubuntu
16.04 LTS.
Red Hat
perl: heap read overflow in regexec.c
vendor_redhat·2018-04-14·CVSS 7.5
CVE-2018-6798 [HIGH] CWE-125 perl: heap read overflow in regexec.c
perl: heap read overflow in regexec.c
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
A heap buffer over read flaw was found in the way Perl regular expression engine handled inputs with invalid UTF-8 characters. An attacker able to provide a specially crafted input to be matched against a regular expression could cause Perl interpreter to crash or disclose portion of its memory.
Statement: Versions of the perl interpreter older than 5.22 are not vulnerable. As a result, the versions of perl as shipped in Red Hat Enterprise Linux version 7, 6 and 5, as well as the versions of rh-perl520-perl as shipped with Red Hat Software Collections are not affecte
Debian
CVE-2018-6798: perl - An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dep...
vendor_debian·2018·CVSS 7.5
CVE-2018-6798 [HIGH] CVE-2018-6798: perl - An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dep...
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
Scope: local
bookworm: resolved (fixed in 5.26.1-6)
bullseye: resolved (fixed in 5.26.1-6)
forky: resolved (fixed in 5.26.1-6)
sid: resolved (fixed in 5.26.1-6)
trixie: resolved (fixed in 5.26.1-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-6798 perl: heap read overflow in regexec.c [fedora-all]
bugzilla·2018-04-16·CVSS 7.5
CVE-2018-6798 [HIGH] CVE-2018-6798 perl: heap read overflow in regexec.c [fedora-all]
CVE-2018-6798 perl: heap read overflow in regexec.c [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1547779,1567777
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after update
suggest_reb
Bugzilla
CVE-2018-6797 perl: heap write overflow in regcomp.c
bugzilla·2018-02-21·CVSS 9.8
CVE-2018-6797 [CRITICAL] CVE-2018-6797 perl: heap write overflow in regcomp.c
CVE-2018-6797 perl: heap write overflow in regcomp.c
A flaw was found in Perl 5. A heap write overflow in regcomp.c file might be exploited when a perl program allows user input of patterns. A crafted regular expression can cause the heap buffer overflow, with control over the bytes written.
Discussion:
Reproducer:
$ perl -e 'qr/0b\N{U+41}\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xDF\xD
Bugzilla
CVE-2018-6798 perl: heap read overflow in regexec.c
bugzilla·2018-02-21·CVSS 7.5
CVE-2018-6798 [HIGH] CVE-2018-6798 perl: heap read overflow in regexec.c
CVE-2018-6798 perl: heap read overflow in regexec.c
A flaw was found in Perl 5. A heap read overflow in regexec.c file may allow an attacker to cause a segmentation fault which might lead to a Denial of Service (DoS) or, possibly, heap memory disclosure.
Matching a crafted locale dependent regular expression can cause a heap buffer read overflow and potentially information disclosure while reporting an error message. That error message includes bytes beyond the end of the string, and possibly beyond the end of the buffer, providing a potential information disclosure if the memory had contained any sensitive information.
Discussion:
Reproducer:
$ valgrind -- perl -e '"\xff" =~ /(?il)\x{100}|\x{100}/;'
==18228== Memcheck, a memory error detector
==18228== Copyright (C) 2002-2017, and GN
http://www.securitytracker.com/id/1040681https://access.redhat.com/errata/RHSA-2018:1192https://rt.perl.org/Public/Bug/Display.html?id=132063https://security.gentoo.org/glsa/201909-01https://usn.ubuntu.com/3625-1/https://www.debian.org/security/2018/dsa-4172https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://www.securitytracker.com/id/1040681https://access.redhat.com/errata/RHSA-2018:1192https://rt.perl.org/Public/Bug/Display.html?id=132063https://security.gentoo.org/glsa/201909-01https://usn.ubuntu.com/3625-1/https://www.debian.org/security/2018/dsa-4172https://www.oracle.com/security-alerts/cpujul2020.html
2018-04-17
Published