Back

CRITICAL

perl: Integer overflow leading to buffer overflow in Perl_my_setenv()

Published Dec 7, 2018

Description

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

Affected products

Remediation

Red Hat statement

This vulnerability is present in versions of perl included with Red Hat Virtualization Hypervisor and Management Appliance, however it is not exposed in any meaningful way. Perl is only included in these images as a dependency of components which do not manipulate ENV, and are not exposed to user input. A future update may address this issue.

Metrics

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 7, 2018
Updated Aug 5, 2024
Reserved Oct 14, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 29, 2018