CVE-2020-10878
published 2020-06-05CVE-2020-10878: Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to…
PriorityP347high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
4.88%
91.1th percentile
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_catalina_10.15.6_security_update_2020-004_mojave_security_update_2020-004 | — | — |
| debian | perl | < perl 5.30.3-1 (bookworm) | perl 5.30.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| oracle | communications_billing_and_revenue_management | — | — |
| oracle | communications_billing_and_revenue_management | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.5.0 | — |
| oracle | communications_eagle_application_processor | 16.1.0 – 16.4.0 | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_lsms | 13.1 – 13.4 | — |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | communications_performance_intelligence_center | 10.3.0.0.0 – 10.3.0.2.1 | — |
| oracle | communications_performance_intelligence_center | 10.4.0.1.0 – 10.4.0.3.1 | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | configuration_manager | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | sd-wan_aware | — | — |
| oracle | sd-wan_aware | — | — |
| oracle | sd-wan_aware | — | — |
| oracle | tekelec_platform_distribution | 7.4.0 – 7.7.1 | — |
| perl | perl | < 5.30.3 | 5.30.3 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.6HIGH
vendor_debian8.6HIGH
vendor_oracle8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Oracle
Oracle Oracle Communications Risk Matrix: Platform (PERL) — CVE-2020-10878
vendor_oracle·2022-10-15·CVSS 8.6
CVE-2020-10878 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (PERL) — CVE-2020-10878
Oracle Oracle Communications Risk Matrix: Platform (PERL) vulnerability
CVE: CVE-2020-10878
CVSS: 8.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Perl) — CVE-2020-10878
vendor_oracle·2022-04-15·CVSS 8.6
CVE-2020-10878 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Perl) — CVE-2020-10878
Oracle Oracle Communications Risk Matrix: Platform (Perl) vulnerability
CVE: CVE-2020-10878
CVSS: 8.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Perl) — CVE-2020-10878
vendor_oracle·2022-01-15·CVSS 8.6
CVE-2020-10878 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Perl) — CVE-2020-10878
Oracle Oracle Communications Risk Matrix: Platform (Perl) vulnerability
CVE: CVE-2020-10878
CVSS: 8.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Perl) — CVE-2020-10878
vendor_oracle·2021-10-15·CVSS 8.6
CVE-2020-10878 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Perl) — CVE-2020-10878
Oracle Oracle Communications Risk Matrix: Platform (Perl) vulnerability
CVE: CVE-2020-10878
CVSS: 8.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: UDC CORE (Perl) — CVE-2020-10878
vendor_oracle·2021-07-15·CVSS 8.6
CVE-2020-10878 [HIGH] Oracle Oracle Communications Applications Risk Matrix: UDC CORE (Perl) — CVE-2020-10878
Oracle Oracle Communications Applications Risk Matrix: UDC CORE (Perl) vulnerability
CVE: CVE-2020-10878
CVSS: 8.6
Protocol: TCP/IP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: EM on Market Place (Perl) — CVE-2020-10878
vendor_oracle·2021-04-15·CVSS 8.6
CVE-2020-10878 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: EM on Market Place (Perl) — CVE-2020-10878
Oracle Oracle Enterprise Manager Risk Matrix: EM on Market Place (Perl) vulnerability
CVE: CVE-2020-10878
CVSS: 8.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2020-10-27·CVSS 8.2
CVE-2020-10878 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
USN-4602-1 fixed several vulnerabilities in Perl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
ManhND discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-10543)
Hugo van der Sanden and Slaven Rezic discovered that Perl incorrectly
handled certain regular expressions. In environments where untrusted
regular expressions are evaluated, a remote attacker could possibly use
this issue to cause Perl to crash
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2020-10-26·CVSS 8.2
CVE-2020-10543 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
ManhND discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-10543)
Hugo van der Sanden and Slaven Rezic discovered that Perl incorrectly
handled certain regular expressions. In environments where untrusted
regular expressions are evaluated, a remote attacker could possibly use
this issue to cause Perl to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2020-10878)
Sergey Aleynikov discovered that Perl incorrectly handled certain regular
expre
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Perl) — CVE-2020-10878
vendor_oracle·2020-10-15·CVSS 8.6
CVE-2020-10878 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Perl) — CVE-2020-10878
Oracle Oracle Communications Applications Risk Matrix: Core (Perl) vulnerability
CVE: CVE-2020-10878
CVSS: 8.6
Protocol: TCP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Apple
CVE-2020-10878: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
vendor_apple·2020-07-15·CVSS 8.6
CVE-2020-10878 [HIGH] CVE-2020-10878: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
Product: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
CVE: CVE-2020-10878
Component: Perl
Impact: An integer overflow in the Perl regular expression compiler may allow a remote attacker to insert instructions into the compiled form of a regular expression
Description: This issue was addressed with improved checks.
Red Hat
perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS
vendor_redhat·2020-06-02·CVSS 8.6
CVE-2020-10878 [HIGH] CWE-190 perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS
perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
Statement: This flaw is an integer overflow triggered when an application compiles a specially crafted, untrusted regular expression pattern supplied by a user, as most applications match untrusted data against a trusted regex pattern.The flaw leads to a corruption of the intermediate language state. While this could theoretically allow an attacker to insert instructions, the resulting behavior is unpredictable, and any potential code execution is likely out
Debian
CVE-2020-10878: perl - Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regki...
vendor_debian·2020·CVSS 8.6
CVE-2020-10878 [HIGH] CVE-2020-10878: perl - Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regki...
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
Scope: local
bookworm: resolved (fixed in 5.30.3-1)
bullseye: resolved (fixed in 5.30.3-1)
forky: resolved (fixed in 5.30.3-1)
sid: resolved (fixed in 5.30.3-1)
trixie: resolved (fixed in 5.30.3-1)
OSV
perl vulnerabilities
osv·2020-10-27·CVSS 8.2
CVE-2020-10543 [HIGH] perl vulnerabilities
perl vulnerabilities
USN-4602-1 fixed several vulnerabilities in Perl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
ManhND discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-10543)
Hugo van der Sanden and Slaven Rezic discovered that Perl incorrectly
handled certain regular expressions. In environments where untrusted
regular expressions are evaluated, a remote attacker could possibly use
this issue to cause Perl to crash, resulting in a denial of service, or
possibly execute arbit
OSV
perl vulnerabilities
osv·2020-10-26·CVSS 8.2
CVE-2020-10543 [HIGH] perl vulnerabilities
perl vulnerabilities
ManhND discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-10543)
Hugo van der Sanden and Slaven Rezic discovered that Perl incorrectly
handled certain regular expressions. In environments where untrusted
regular expressions are evaluated, a remote attacker could possibly use
this issue to cause Perl to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2020-10878)
Sergey Aleynikov discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions a
OSV
CVE-2020-10878: Perl before 5
osv·2020-06-05·CVSS 8.6
CVE-2020-10878 [HIGH] CVE-2020-10878: Perl before 5
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
OSV
CVE-2020-10878: Perl before 5
osv·2020-06-01·CVSS 8.6
CVE-2020-10878 [HIGH] CVE-2020-10878: Perl before 5
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. An application written in Perl would only be vulnerable to this flaw if it evaluates regular expressions supplied by the attacker. Evaluating regular expressions in this fashion is known to be dangerous since the regular expression engine does not protect against denial of service attacks in this usage scenario.]
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10878 perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS [fedora-all]
bugzilla·2020-06-06·CVSS 8.6
CVE-2020-10878 [HIGH] CVE-2020-10878 perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS [fedora-all]
CVE-2020-10878 perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg com
Bugzilla
CVE-2020-10878 perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS
bugzilla·2020-05-20·CVSS 8.6
CVE-2020-10878 [HIGH] CVE-2020-10878 perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS
CVE-2020-10878 perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS
This vulnerability is an attacker controlled corruption of the
intermediate language state of a compiled regular expression. The
corruption occurs due to integer overflows in the calculation of offsets
between instructions for the regular expression engine. An attacker
could abuse this behavior to insert instructions into the compiled form
of a Perl regular expression.
Discussion:
Acknowledgments:
Name: Hugo van der Sanden, Slaven Rezic
---
(In reply to Todd Cullum from comment #5)
> Mitigation:
>
> To mitigate this flaw, developers should not pass untrusted or uncontrolled
> data to the Perl regular expression engine; especially in cases where the
> regu
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.htmlhttps://github.com/Perl/perl5/blob/blead/pod/perl5303delta.podhttps://github.com/Perl/perl5/compare/v5.30.2...v5.30.3https://github.com/perl/perl5/commit/0a320d753fe7fca03df259a4dfd8e641e51edaa8https://github.com/perl/perl5/commit/3295b48defa0f8570114877b063fe546dd348b3chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/https://security.gentoo.org/glsa/202006-03https://security.netapp.com/advisory/ntap-20200611-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.htmlhttps://github.com/Perl/perl5/blob/blead/pod/perl5303delta.podhttps://github.com/Perl/perl5/compare/v5.30.2...v5.30.3https://github.com/perl/perl5/commit/0a320d753fe7fca03df259a4dfd8e641e51edaa8https://github.com/perl/perl5/commit/3295b48defa0f8570114877b063fe546dd348b3chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/https://security.gentoo.org/glsa/202006-03https://security.netapp.com/advisory/ntap-20200611-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-06-05
Published