Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19831
HistoryMay 16, 2019 - 3:25 a.m.

Information Disclosure

2019-05-1603:25:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.004 Low

EPSS

Percentile

73.7%

Perl is vulnerable to information disclosure vulnerability. The vulnerability exists in the function S_grok_bslash_N of the file regcomp.c of the component Regex Handler. A heap-based buffer-overflow vulnerability could occur because it fails to properly bounds-check user-supplied input. Attackers could execute arbitrary code on the affected application via a crafted regular expression to access sensitive information from process memory. Failed attempts will likely cause a denial of service condition.

References