Perl 'Perl_reg_numbered_buff_fetch()' Function Remote Denial of Service Vulnerability
BID:47006
Info
Perl 'Perl_reg_numbered_buff_fetch()' Function Remote Denial of Service Vulnerability
| Bugtraq ID: | 47006 |
| Class: | Design Error |
| CVE: |
CVE-2010-4777 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2011 12:00AM |
| Updated: | Feb 13 2014 01:05AM |
| Credit: | Vladimir Perepelitsa |
| Vulnerable: |
Larry Wall Perl 5.12.1 Larry Wall Perl 5.10.1 Larry Wall Perl 5.10 Larry Wall Perl 5.9.3 Larry Wall Perl 5.9.2 Larry Wall Perl 5.8.8 Larry Wall Perl 5.8.7 Larry Wall Perl 5.8.6 Larry Wall Perl 5.8.5 Larry Wall Perl 5.8.4 -5 Larry Wall Perl 5.8.4 -4 Larry Wall Perl 5.8.4 -3 Larry Wall Perl 5.8.4 -2.3 Larry Wall Perl 5.8.4 -2 Larry Wall Perl 5.8.4 -1 Larry Wall Perl 5.8.4 Larry Wall Perl 5.8.3 Larry Wall Perl 5.8.1 Larry Wall Perl 5.8 .0-88.3 Larry Wall Perl 5.8 Larry Wall Perl 5.6.1 Larry Wall Perl 5.6 Larry Wall Perl 5.0 05_003 Larry Wall Perl 5.0 05 Larry Wall Perl 5.0 04_05 Larry Wall Perl 5.0 04_04 Larry Wall Perl 5.0 04 Larry Wall Perl 5.0 03 Larry Wall Perl 5.14 Larry Wall Perl 5.12 Larry Wall Perl 5.10 |
| Not Vulnerable: | |
Discussion
Perl 'Perl_reg_numbered_buff_fetch()' Function Remote Denial of Service Vulnerability
Perl is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an application implemented with affected perl code to abort, denying service to legitimate users.
Perl is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an application implemented with affected perl code to abort, denying service to legitimate users.
Exploit / POC
Perl 'Perl_reg_numbered_buff_fetch()' Function Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Perl 'Perl_reg_numbered_buff_fetch()' Function Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Perl 'Perl_reg_numbered_buff_fetch()' Function Remote Denial of Service Vulnerability
References:
References:
- #76538: Assertion failed: (rx->sublen >= (s - rx->subbeg) + i), function Perl_re (Vladimir Perepelitsa)
- Perl Home Page (Perl)