CVE-2020-10543
published 2020-06-05CVE-2020-10543: Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
PriorityP350high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
11.33%
95.5th percentile
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.30.3-1 (bookworm) | perl 5.30.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| oracle | communications_billing_and_revenue_management | — | — |
| oracle | communications_billing_and_revenue_management | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.5.0 | — |
| oracle | communications_eagle_application_processor | 16.1.0 – 16.4.0 | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_lsms | 13.1 – 13.4 | — |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | communications_performance_intelligence_center | 10.3.0.0.0 – 10.3.0.2.1 | — |
| oracle | communications_performance_intelligence_center | 10.4.0.1.0 – 10.4.0.3.1 | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | configuration_manager | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | sd-wan_edge | — | — |
| oracle | sd-wan_edge | — | — |
| oracle | sd-wan_edge | — | — |
| oracle | tekelec_platform_distribution | 7.4.0 – 7.7.1 | — |
| perl | perl | < 5.30.3 | 5.30.3 |
| perl | perl | >= 0 < 5.30.3-1 | 5.30.3-1 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv8.2HIGH
vendor_oracle8.6HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Oracle
Oracle Oracle Communications Risk Matrix: Realtime db (Perl) — CVE-2020-10543
vendor_oracle·2021-10-15·CVSS 8.2
CVE-2020-10543 [HIGH] Oracle Oracle Communications Risk Matrix: Realtime db (Perl) — CVE-2020-10543
Oracle Oracle Communications Risk Matrix: Realtime db (Perl) vulnerability
CVE: CVE-2020-10543
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Communications Risk Matrix: Publications (Perl) — CVE-2020-10543
vendor_oracle·2021-07-15·CVSS 8.6
CVE-2020-10543 [HIGH] Oracle Oracle Communications Risk Matrix: Publications (Perl) — CVE-2020-10543
Oracle Oracle Communications Risk Matrix: Publications (Perl) vulnerability
CVE: CVE-2020-10543
CVSS: 8.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2020-10-27·CVSS 8.2
CVE-2020-10878 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
USN-4602-1 fixed several vulnerabilities in Perl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
ManhND discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-10543)
Hugo van der Sanden and Slaven Rezic discovered that Perl incorrectly
handled certain regular expressions. In environments where untrusted
regular expressions are evaluated, a remote attacker could possibly use
this issue to cause Perl to crash
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2020-10-26·CVSS 8.2
CVE-2020-10543 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
ManhND discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-10543)
Hugo van der Sanden and Slaven Rezic discovered that Perl incorrectly
handled certain regular expressions. In environments where untrusted
regular expressions are evaluated, a remote attacker could possibly use
this issue to cause Perl to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2020-10878)
Sergey Aleynikov discovered that Perl incorrectly handled certain regular
expre
Red Hat
perl: heap-based buffer overflow in regular expression compiler leads to DoS
vendor_redhat·2020-06-02·CVSS 8.2
CVE-2020-10543 [HIGH] CWE-190 perl: heap-based buffer overflow in regular expression compiler leads to DoS
perl: heap-based buffer overflow in regular expression compiler leads to DoS
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
Statement: A heap buffer overflow vulnerability exists in the regular expression compiler of Perl packages shipped with Red Hat Enterprise Linux 6, 7, and 8. The flaw occurs in the S_study_chunk() function of regcomp.c due to a signed size_t integer overflow in storage space calculations for nested regular expression quantifiers. When untrusted regular expressions are compiled, this can lead to out-of-bounds memory writes with attacker-controlled data. The vulnerability does not depend on the data being matched, but rather on the regular expression itself. On Red Hat
Debian
CVE-2020-10543: perl - Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow becau...
vendor_debian·2020·CVSS 8.2
CVE-2020-10543 [HIGH] CVE-2020-10543: perl - Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow becau...
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
Scope: local
bookworm: resolved (fixed in 5.30.3-1)
bullseye: resolved (fixed in 5.30.3-1)
forky: resolved (fixed in 5.30.3-1)
sid: resolved (fixed in 5.30.3-1)
trixie: resolved (fixed in 5.30.3-1)
OSV
perl vulnerabilities
osv·2020-10-27·CVSS 8.2
CVE-2020-10543 [HIGH] perl vulnerabilities
perl vulnerabilities
USN-4602-1 fixed several vulnerabilities in Perl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
ManhND discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-10543)
Hugo van der Sanden and Slaven Rezic discovered that Perl incorrectly
handled certain regular expressions. In environments where untrusted
regular expressions are evaluated, a remote attacker could possibly use
this issue to cause Perl to crash, resulting in a denial of service, or
possibly execute arbit
OSV
perl vulnerabilities
osv·2020-10-26·CVSS 8.2
CVE-2020-10543 [HIGH] perl vulnerabilities
perl vulnerabilities
ManhND discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-10543)
Hugo van der Sanden and Slaven Rezic discovered that Perl incorrectly
handled certain regular expressions. In environments where untrusted
regular expressions are evaluated, a remote attacker could possibly use
this issue to cause Perl to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2020-10878)
Sergey Aleynikov discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions a
OSV
CVE-2020-10543: Perl before 5
osv·2020-06-05·CVSS 8.2
CVE-2020-10543 [HIGH] CVE-2020-10543: Perl before 5
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
OSV
CVE-2020-10543: Perl before 5
osv·2020-06-01·CVSS 8.2
CVE-2020-10543 [HIGH] CVE-2020-10543: Perl before 5
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. An application written in Perl would only be vulnerable to this flaw if it evaluates regular expressions supplied by the attacker. Evaluating regular expressions in this fashion is known to be dangerous since the regular expression engine does not protect against denial of service attacks in this usage scenario. Additionally, the target system needs a sufficient amount of memory to allocate partial expansions of the nested quantifiers prior to the overflow occurring. This requirement is unlikely to be met on 64bit systems.]
No detection rules found.
No public exploits indexed.
HackerOne
[CVE-2020-10543] Buffer overflow caused by a crafted regular expression
hackerone·2020-11-09·CVSS 8.2
CVE-2020-10543 [HIGH] [CVE-2020-10543] Buffer overflow caused by a crafted regular expression
[CVE-2020-10543] Buffer overflow caused by a crafted regular expression
CVE ID: CVE-2020-10543
See:
+ https://metacpan.org/pod/release/XSAWYERX/perl-5.30.3/pod/perldelta.pod
+ https://metacpan.org/pod/release/XSAWYERX/perl-5.28.3/pod/perldelta.pod
## Impact
Potential RCE
Bugzilla
CVE-2020-10543 perl: heap-based buffer overflow in regular expression compiler leads to DoS [fedora-all]
bugzilla·2020-06-06·CVSS 8.2
CVE-2020-10543 [HIGH] CVE-2020-10543 perl: heap-based buffer overflow in regular expression compiler leads to DoS [fedora-all]
CVE-2020-10543 perl: heap-based buffer overflow in regular expression compiler leads to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2020-10543 perl: heap-based buffer overflow in regular expression compiler leads to DoS
bugzilla·2020-05-20·CVSS 8.2
CVE-2020-10543 [HIGH] CVE-2020-10543 perl: heap-based buffer overflow in regular expression compiler leads to DoS
CVE-2020-10543 perl: heap-based buffer overflow in regular expression compiler leads to DoS
There is a heap buffer overflow in Perl's regular expression compiler
that overwrites memory allocated after the regular expression storage
space with attacker supplied data. The heap overflow occurs due to a
signed size_t integer overflow in the storage space calculations for
nested regular expression quantifiers.
Discussion:
Acknowledgments:
Name: ManhND (Tarantula Team), VinCSS (Vingroup)
---
(In reply to Todd Cullum from comment #4)
> Mitigation:
>
> To mitigate this flaw, developers should not pass untrusted or uncontrolled
> input data to the Perl regex engine for evaluation.
That's not correct. The flaw requires passing an untrusted regular expression to the Perl regex compiler. The fl
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.htmlhttps://github.com/Perl/perl5/blob/blead/pod/perl5303delta.podhttps://github.com/Perl/perl5/compare/v5.30.2...v5.30.3https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03edhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/https://security.gentoo.org/glsa/202006-03https://security.netapp.com/advisory/ntap-20200611-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.htmlhttps://github.com/Perl/perl5/blob/blead/pod/perl5303delta.podhttps://github.com/Perl/perl5/compare/v5.30.2...v5.30.3https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03edhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/https://security.gentoo.org/glsa/202006-03https://security.netapp.com/advisory/ntap-20200611-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-06-05
Published