Back

HIGH

perl: Heap buffer overflow in regular expression compiler

Published Sep 19, 2017

Description

Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.

Affected products

Remediation

Red Hat statement

This issue does not affect perl versions older than 5.18. Perl as shipped in Red Hat Enterprise Linux 7 and older are not affected by this vulnerability.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 19, 2017
Updated Aug 5, 2024
Reserved Aug 11, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 12, 2017