Lucene search

K
osvGoogleOSV:DSA-1556-2
HistoryApr 24, 2008 - 12:00 a.m.

perl - denial of service

2008-04-2400:00:00
Google
osv.dev
22

EPSS

0.014

Percentile

86.2%

It has been discovered that the Perl interpreter may encounter a buffer
overflow condition when compiling certain regular expressions containing
Unicode characters. This also happens if the offending characters are
contained in a variable reference protected by the \Q…\E quoting
construct. When encountering this condition, the Perl interpreter
typically crashes, but arbitrary code execution cannot be ruled out.

For the stable distribution (etch), this problem has been fixed in
version 5.8.8-7etch3.

The unstable distribution (sid) will be fixed soon.

We recommend that you upgrade your perl packages.