CVE-2023-47038
published 2023-12-18CVE-2023-47038: A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.83%
53.6th percentile
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.36.0-7+deb12u1 (bookworm) | perl 5.36.0-7+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| perl | perl | >= 0 < 5.32.1-4+deb11u3 | 5.32.1-4+deb11u3 |
| perl | perl | >= 0 < 5.36.0-7+deb12u1 | 5.36.0-7+deb12u1 |
| perl | perl | >= 0 < 5.36.0-10 | 5.36.0-10 |
| perl | perl | >= 0 < 5.36.0-10 | 5.36.0-10 |
| perl | perl | >= 0 < 5.30.0-9ubuntu0.5 | 5.30.0-9ubuntu0.5 |
| perl | perl | >= 0 < 5.34.0-3ubuntu1.3 | 5.34.0-3ubuntu1.3 |
| perl | perl | 5.30.0 – 5.38.0 | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_eus | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC INS
cisa_ics·2024-11-14
Siemens SINEC INS
ICS Advisory
##
Siemens SINEC INS
Release DateNovember 14, 2024
Alert CodeICSA-24-319-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.9
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Authentication, Out-of-bounds Write, Ineffici
Red Hat
perl: Perl security bypass
vendor_redhat·2023-12-03·CVSS 7.0
CVE-2023-47100 [HIGH] CWE-755 perl: Perl security bypass
perl: Perl security bypass
A flaw was found in Perl due to improper handling of the property name by the S_parse_uniprop_string function in regcomp.c. This issue could allow an attacker to to bypass security restrictions and use a specially crafted regular expression input to write to unallocated space.
Statement: This flaw was found to be a duplicate of CVE-2023-47038. Please see https://access.redhat.com/security/cve/CVE-2023-47038 for information about affected products and security errata.
Package: perl (Red Hat Enterprise Linux 6) - Not affected
Package: perl (Red Hat Enterprise Linux 7) - Not affected
Package: perl (Red Hat Enterprise Linux 8) - Not affected
Package: perl:5.32/perl (Red Hat Enterprise Linux 8) - Not affected
Package: perl (Red Hat Enterprise Linux 9) - Not aff
BSD
OpenBSD 7.3 Errata 021: SECURITY FIX
bsd_advisories·2023-11-29·CVSS 7.0
CVE-2023-47038 [HIGH] OpenBSD 7.3 Errata 021: SECURITY FIX
OpenBSD 7.3 Errata 021: SECURITY FIX
021: SECURITY FIX: November 29, 2023
All architectures A crafted regular expression when compiled by perl can cause a one-byte attacker controlled buffer overflow in a heap allocated buffer. CVE-2023-47038
BSD
OpenBSD 7.4 Errata 007: SECURITY FIX
bsd_advisories·2023-11-29·CVSS 7.0
CVE-2023-47038 [HIGH] OpenBSD 7.4 Errata 007: SECURITY FIX
OpenBSD 7.4 Errata 007: SECURITY FIX
007: SECURITY FIX: November 29, 2023
All architectures A crafted regular expression when compiled by perl can cause a one-byte attacker controlled buffer overflow in a heap allocated buffer. CVE-2023-47038
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2023-11-27·CVSS 9.8
CVE-2022-48522 [CRITICAL] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
It was discovered that Perl incorrectly handled printing certain warning
messages. An attacker could possibly use this issue to cause Perl to
consume resources, leading to a denial of service. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-48522)
Nathan Mills discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-47038)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl: Write past buffer end via illegal user-defined Unicode property
vendor_redhat·2023-11-25·CVSS 7.0
CVE-2023-47038 [HIGH] CWE-122 perl: Write past buffer end via illegal user-defined Unicode property
perl: Write past buffer end via illegal user-defined Unicode property
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
Statement: For this vulnerability in Perl, a successful exploitation may involve navigating through intricate aspects of the code related to user-defined Unicode properties and executing an attack that writes past the buffer end. So the higher attack complexity implies that it would be more
Debian
CVE-2023-47038: perl - A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when ...
vendor_debian·2023·CVSS 7.0
CVE-2023-47038 [HIGH] CVE-2023-47038: perl - A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when ...
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
Scope: local
bookworm: resolved (fixed in 5.36.0-7+deb12u1)
bullseye: resolved (fixed in 5.32.1-4+deb11u3)
forky: resolved (fixed in 5.36.0-10)
sid: resolved (fixed in 5.36.0-10)
trixie: resolved (fixed in 5.36.0-10)
GHSA
GHSA-96fh-9q43-rmjh: A vulnerability was found in perl
ghsa_unreviewed·2023-12-30
CVE-2023-47038 [HIGH] CWE-122 GHSA-96fh-9q43-rmjh: A vulnerability was found in perl
A vulnerability was found in perl. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
OSV
CVE-2023-47038: A vulnerability was found in perl 5
osv·2023-12-18·CVSS 7.8
CVE-2023-47038 [HIGH] CVE-2023-47038: A vulnerability was found in perl 5
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
OSV
perl vulnerabilities
osv·2023-11-27·CVSS 9.8
CVE-2022-48522 [CRITICAL] perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled printing certain warning
messages. An attacker could possibly use this issue to cause Perl to
consume resources, leading to a denial of service. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-48522)
Nathan Mills discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-47038)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:2228https://access.redhat.com/errata/RHSA-2024:3128https://access.redhat.com/security/cve/CVE-2023-47038https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056746https://bugzilla.redhat.com/show_bug.cgi?id=2249523https://access.redhat.com/errata/RHSA-2024:2228https://access.redhat.com/errata/RHSA-2024:3128https://access.redhat.com/security/cve/CVE-2023-47038https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056746https://bugzilla.redhat.com/show_bug.cgi?id=2249523https://github.com/Perl/perl5/commit/12c313ce49b36160a7ca2e9b07ad5bd92ee4a010https://github.com/Perl/perl5/commit/7047915eef37fccd93e7cd985c29fe6be54650b6https://github.com/Perl/perl5/commit/ff1f9f59360afeebd6f75ca1502f5c3ebf077da3https://github.com/aquasecurity/trivy/discussions/8400https://lists.fedoraproject.org/archives/list/[email protected]/message/GNEEWAACXQCEEAKSG7XX2D5YDRWLCIZJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/UMDZZ4SCEW6FRWZDMXGAKZ35THTAWFG6/https://perldoc.perl.org/perl5382delta#CVE-2023-47038-Write-past-buffer-end-via-illegal-user-defined-Unicode-propertyhttps://ubuntu.com/security/CVE-2023-47100https://www.suse.com/security/cve/CVE-2023-47100.html
2023-12-18
Published