CVE-2018-6797

Name
CVE-2018-6797
Description
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://www.debian.org/security/2018/dsa-4172
Patch https://rt.perl.org/Public/Bug/Display.html?id=132227
Third Party Advisory http://www.securitytracker.com/id/1040681
Third Party Advisory https://access.redhat.com/errata/RHSA-2018:1192
Third Party Advisory https://usn.ubuntu.com/3625-1/
Third Party Advisory http://www.securitytracker.com/id/1042004
GENTOO https://security.gentoo.org/glsa/201909-01
MISC https://www.oracle.com/security-alerts/cpujul2020.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* debian_linux == None == 8.0
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* debian_linux == None == 9.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
perl edge-main 5.26.2-r0 None fixed
perl 3.22-main 5.26.2-r0 None fixed
perl 3.21-main 5.26.2-r0 None fixed
perl 3.20-main 5.26.2-r0 None fixed
perl 3.19-main 5.26.2-r0 None fixed
perl 3.18-main 5.26.2-r0 None fixed
perl 3.17-main 5.26.2-r0 None fixed
perl 3.12-main 5.26.2-r0 None fixed
perl 3.11-main 5.26.2-r0 None fixed
perl 3.10-main 5.26.2-r0 None fixed