Back

CRITICAL

perl: out-of-bounds read and buffer overflow in functions VDir::MapPathA and VDir::MapPathW via a crafted drive letter or a pInName argument

Published Feb 7, 2017

Description

The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.

Affected products

Remediation

Red Hat statement

This is a Microsoft Windows only flaw in perl as mentioned in the original report at: https://github.com/Perl/perl5/issues/15067#issuecomment-544077033

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 7, 2017
Updated Aug 6, 2024
Reserved Dec 17, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 11, 2016