Perl Unicode '\Q...\E' Quoting Construct Regular Expression Buffer Overflow Vulnerability
BID:28928
Info
Perl Unicode '\Q...\E' Quoting Construct Regular Expression Buffer Overflow Vulnerability
| Bugtraq ID: | 28928 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1927 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2008 12:00AM |
| Updated: | Apr 13 2015 09:29PM |
| Credit: | Niko Tyni |
| Vulnerable: |
VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.5 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP2 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP2 DEBUGINFO SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE Linux Desktop 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 rPath rPath Linux 2 rPath rPath Linux 1 rPath Appliance Platform Linux Service 2 rPath Appliance Platform Linux Service 1 Redhat Fedora 7 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Certificate Server 7.3 Redhat Application Stack v1 for Enterprise Linux ES 4 Redhat Application Stack v1 for Enterprise Linux AS 4 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Larry Wall Perl 5.8.8 IPCop IPCop 1.4.20 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Voice Portal 3.0 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 4.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Meeting Exchange 5.0 .0.52 Avaya Intuity AUDIX LX 2.0 Avaya Intuity LX 2.0 Avaya Intuity LX Avaya EMMC 1.021 Avaya EMMC 1.017 Avaya EMMC 0 Avaya Communication Manager 2.0.1 Avaya Communication Manager 2.0 Avaya Communication Manager 5.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya Communication Manager 2.2 Avaya Communication Manager 2.1 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura Application Enablement Services 3.1.5 Avaya Aura Application Enablement Services 4.2 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.5 |
| Not Vulnerable: |
IPCop IPCop 1.4.21 |
Discussion
Perl Unicode '\Q...\E' Quoting Construct Regular Expression Buffer Overflow Vulnerability
Perl is prone to a buffer-overflow vulnerability because it fails to sufficiently bounds-check user-supplied input.
Successfully exploiting this issue may allow attackers to execute arbitrary machine code in the context of Perl applications using regular expressions in a vulnerable manner. This facilitates the remote compromise of affected computers. Failed exploits can cause denial-of-service conditions.
Perl 5.8.8 is vulnerable; other versions may also be affected.
NOTE: This issue may be related to BID 26350 ('Perl Unicode Regular Expression Buffer Overflow Vulnerability').
Perl is prone to a buffer-overflow vulnerability because it fails to sufficiently bounds-check user-supplied input.
Successfully exploiting this issue may allow attackers to execute arbitrary machine code in the context of Perl applications using regular expressions in a vulnerable manner. This facilitates the remote compromise of affected computers. Failed exploits can cause denial-of-service conditions.
Perl 5.8.8 is vulnerable; other versions may also be affected.
NOTE: This issue may be related to BID 26350 ('Perl Unicode Regular Expression Buffer Overflow Vulnerability').
Exploit / POC
Perl Unicode '\Q...\E' Quoting Construct Regular Expression Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Perl Unicode '\Q...\E' Quoting Construct Regular Expression Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 6.06 LTS i386
Ubuntu Ubuntu Linux 7.10 lpia
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.6
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
-
Ubuntu libarchive-tar-perl_1.31-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/liba/libarchive-tar-perl/l ibarchive-tar-perl_1.31-1ubuntu0.1_all.deb -
Ubuntu libcgi-fast-perl_5.8.8-7ubuntu3.4_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/p/perl/libcgi-fast-per l_5.8.8-7ubuntu3.4_all.deb -
Ubuntu libperl-dev_5.8.8-7ubuntu3.4_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/libperl-dev_5.8.8-7 ubuntu3.4_powerpc.deb -
Ubuntu libperl5.8_5.8.8-7ubuntu3.4_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/libperl5.8_5.8.8-7u buntu3.4_powerpc.deb -
Ubuntu perl-base_5.8.8-7ubuntu3.4_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-base_5.8.8-7ub untu3.4_powerpc.deb -
Ubuntu perl-debug_5.8.8-7ubuntu3.4_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-debug_5.8.8-7u buntu3.4_powerpc.deb -
Ubuntu perl-doc_5.8.8-7ubuntu3.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-doc_5.8.8-7ubu ntu3.4_all.deb -
Ubuntu perl-modules_5.8.8-7ubuntu3.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-modules_5.8.8- 7ubuntu3.4_all.deb -
Ubuntu perl-suid_5.8.8-7ubuntu3.4_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-suid_5.8.8-7ub untu3.4_powerpc.deb -
Ubuntu perl_5.8.8-7ubuntu3.4_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl_5.8.8-7ubuntu3 .4_powerpc.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu libarchive-tar-perl_1.36-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/liba/libarchive-tar-perl/l ibarchive-tar-perl_1.36-1ubuntu0.1_all.deb -
Ubuntu libcgi-fast-perl_5.8.8-12ubuntu0.3_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/p/perl/libcgi-fast-per l_5.8.8-12ubuntu0.3_all.deb -
Ubuntu libcgi-fast-perl_5.8.8-12ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/p/perl/libcgi-fast-per l_5.8.8-12ubuntu0.4_all.deb -
Ubuntu libperl-dev_5.8.8-12ubuntu0.3_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/libperl-dev_5.8.8-12ubuntu0.3 _lpia.deb -
Ubuntu libperl-dev_5.8.8-12ubuntu0.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/libperl-dev_5.8.8-12ubuntu0.4 _lpia.deb -
Ubuntu libperl5.8_5.8.8-12ubuntu0.3_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/libperl5.8_5.8.8-12ubuntu0.3_ lpia.deb -
Ubuntu libperl5.8_5.8.8-12ubuntu0.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/libperl5.8_5.8.8-12ubuntu0.4_ lpia.deb -
Ubuntu perl-base_5.8.8-12ubuntu0.3_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl-base_5.8.8-12ubuntu0.3_l pia.deb -
Ubuntu perl-base_5.8.8-12ubuntu0.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl-base_5.8.8-12ubuntu0.4_l pia.deb -
Ubuntu perl-debug_5.8.8-12ubuntu0.3_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl-debug_5.8.8-12ubuntu0.3_ lpia.deb -
Ubuntu perl-debug_5.8.8-12ubuntu0.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl-debug_5.8.8-12ubuntu0.4_ lpia.deb -
Ubuntu perl-doc_5.8.8-12ubuntu0.3_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-doc_5.8.8-12ub untu0.3_all.deb -
Ubuntu perl-doc_5.8.8-12ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-doc_5.8.8-12ub untu0.4_all.deb -
Ubuntu perl-modules_5.8.8-12ubuntu0.3_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-modules_5.8.8- 12ubuntu0.3_all.deb -
Ubuntu perl-modules_5.8.8-12ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-modules_5.8.8- 12ubuntu0.4_all.deb -
Ubuntu perl-suid_5.8.8-12ubuntu0.3_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl-suid_5.8.8-12ubuntu0.3_l pia.deb -
Ubuntu perl-suid_5.8.8-12ubuntu0.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl-suid_5.8.8-12ubuntu0.4_l pia.deb -
Ubuntu perl_5.8.8-12ubuntu0.3_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl_5.8.8-12ubuntu0.3_lpia.d eb -
Ubuntu perl_5.8.8-12ubuntu0.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl_5.8.8-12ubuntu0.4_lpia.d eb
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu libarchive-tar-perl_1.26-2ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/liba/libarchive-tar-perl/l ibarchive-tar-perl_1.26-2ubuntu0.1_all.deb -
Ubuntu libcgi-fast-perl_5.8.7-10ubuntu1.2_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/p/perl/libcgi-fast-per l_5.8.7-10ubuntu1.2_all.deb -
Ubuntu libperl-dev_5.8.7-10ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/libperl-dev_5.8.7-1 0ubuntu1.2_i386.deb -
Ubuntu libperl5.8_5.8.7-10ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/libperl5.8_5.8.7-10 ubuntu1.2_i386.deb -
Ubuntu perl-base_5.8.7-10ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-base_5.8.7-10u buntu1.2_i386.deb -
Ubuntu perl-debug_5.8.7-10ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/p/perl/perl-debug_5.8. 7-10ubuntu1.2_i386.deb -
Ubuntu perl-doc_5.8.7-10ubuntu1.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-doc_5.8.7-10ub untu1.2_all.deb -
Ubuntu perl-modules_5.8.7-10ubuntu1.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-modules_5.8.7- 10ubuntu1.2_all.deb -
Ubuntu perl-suid_5.8.7-10ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-suid_5.8.7-10u buntu1.2_i386.deb -
Ubuntu perl_5.8.7-10ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl_5.8.7-10ubuntu 1.2_i386.deb
Ubuntu Ubuntu Linux 7.10 lpia
-
Ubuntu libarchive-tar-perl_1.31-1ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/liba/libarchive-tar-perl/l ibarchive-tar-perl_1.31-1ubuntu0.1_all.deb -
Ubuntu libcgi-fast-perl_5.8.8-7ubuntu3.4_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/p/perl/libcgi-fast-per l_5.8.8-7ubuntu3.4_all.deb -
Ubuntu libperl-dev_5.8.8-7ubuntu3.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/libperl-dev_5.8.8-7ubuntu3.4_ lpia.deb -
Ubuntu libperl5.8_5.8.8-7ubuntu3.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/libperl5.8_5.8.8-7ubuntu3.4_l pia.deb -
Ubuntu perl-base_5.8.8-7ubuntu3.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl-base_5.8.8-7ubuntu3.4_lp ia.deb -
Ubuntu perl-debug_5.8.8-7ubuntu3.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl-debug_5.8.8-7ubuntu3.4_l pia.deb -
Ubuntu perl-doc_5.8.8-7ubuntu3.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-doc_5.8.8-7ubu ntu3.4_all.deb -
Ubuntu perl-modules_5.8.8-7ubuntu3.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/p/perl/perl-modules_5.8.8- 7ubuntu3.4_all.deb -
Ubuntu perl-suid_5.8.8-7ubuntu3.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl-suid_5.8.8-7ubuntu3.4_lp ia.deb -
Ubuntu perl_5.8.8-7ubuntu3.4_lpia.deb
http://ports.ubuntu.com/pool/main/p/perl/perl_5.8.8-7ubuntu3.4_lpia.de b
Apple Mac OS X 10.4.11
-
Apple SecUpd2009-001Intel.dmg
for Intel
http://support.apple.com/downloads/Security_Update_2009_001__Tiger_Int el_ -
Apple SecUpd2009-001PPC.dmg
for PPC
http://support.apple.com/downloads/Security_Update_2009_001__Tiger_PPC _
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2009-001PPC.dmg
for PPC
http://support.apple.com/downloads/Security_Update_2009_001__Server_Ti ger_PPC_ -
Apple SecUpdSrvr2009-001Univ.dmg
Universal
http://support.apple.com/downloads/Security_Update_2009_001__Server_Un iversal_
Apple Mac OS X 10.5.6
-
Apple SecUpd2009-001.dmg
http://support.apple.com/downloads/Security_Update_2009_001__Leopard_
References
Perl Unicode '\Q...\E' Quoting Construct Regular Expression Buffer Overflow Vulnerability
References:
References:
- Debian Bug # 454792 double free and segfault on utf8 containing regexes version (Debian Linux)
- IPCop 1.4.21 Release Notes (IPCop)
- IPCop Homepage (IPCop)
- Perl Home Page (Perl)
- This Week on perl5-porters - 6-12 April 2008 (David Landgren)
- VMSA-2008-0013 Updated ESX packages for OpenSSL, net-snmp, perl (VMware Security Team
) - ASA-2008-317 - perl security update (RHSA-2008-0532) (Avaya)
- ASA-2008-361 - perl security update (Avaya)
- RHSA-2008:0522-4 perl security update (Red Hat)
- RHSA-2008:0532-1 - perl security update (Red Hat)