Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19832
HistoryMay 16, 2019 - 3:25 a.m.

Remote Code Execution

2019-05-1603:25:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.015 Low

EPSS

Percentile

86.8%

Perl is vulnerable to remote code execution vulnerability. The vulnerability exists in the function S_regatom of the file regcomp.c of the component Regex Handler. An integer-overflow and a heap-based buffer-overflow vulnerability occur because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. Attackers could exploit these issues to execute arbitrary code on the affected application and failed attempts will likely cause a denial service of condition.