Perl CVE-2013-1667 Input Rehashing Denial of Service Vulnerability
BID:58311
Info
Perl CVE-2013-1667 Input Rehashing Denial of Service Vulnerability
| Bugtraq ID: | 58311 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-1667 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2013 12:00AM |
| Updated: | Jul 29 2016 05:00PM |
| Credit: | Ricardo Signes |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 93.E0.21C Xerox FreeFlow Print Server (FFPS) 91.D2.32 Xerox FreeFlow Print Server (FFPS) 82.D1.44 Xerox FreeFlow Print Server (FFPS) 81.D0.73 Xerox FreeFlow Print Server (FFPS) 73.D2.33 Xerox FreeFlow Print Server (FFPS) 73.C5.11 Ubuntu Ubuntu Linux 8.04 LTS 0 Ubuntu Ubuntu Linux 12.10 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 SuSE SUSE Linux Enterprise Server for VMware 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE Suse Linux Enterprise Desktop 11 SP2 SuSE Suse Linux Enterprise Desktop 10 SP4 Slackware Linux x86_64 -current Slackware Linux 14.0 x86_64 Slackware Linux 14.0 Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux -current S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 12.2 S.u.S.E. openSUSE 12.1 S.u.S.E. openSUSE 11.4 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Perl.org Perl 5.12 Perl.org Perl 5.10.1 Perl.org Perl 5.10 Perl.org Perl 5.8.2 Perl.org Perl 5.16.2 Perl.org Perl 5.16.1 Perl.org Perl 5.15.5 Perl.org Perl 5.14.2 Perl.org Perl 5.14.1 Oracle VM Server for x86 3.4 Oracle VM Server for x86 3.3 Oracle VM Server for x86 3.2 Oracle Solaris 11.1 Oracle Solaris 10 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Juniper CTPOS 7.1R Juniper CTPOS 7.0r4 Juniper CTPOS 6.6R5 Juniper CTPOS 6.6R2 Juniper CTPOS 6.6R1 IBM AIX 7.1 IBM AIX 6.1 HP HP-UX B.11.31 HP HP-UX B.11.11 Gentoo Linux EMC VPLEX GeoSynchrony 5.2.1 EMC VPLEX GeoSynchrony 5.2 SP1 EMC VPLEX GeoSynchrony 4.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya Voice Portal 5.1.3 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP3 Avaya Voice Portal 5.1 SP2 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Proactive Contact 5.1 Avaya Proactive Contact 5.0 Avaya one-X Client Enablement Services 6.2 Avaya one-X Client Enablement Services 6.1 Avaya one-X Client Enablement Services 6.0 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP2 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IP Office Server Edition 8.1 Avaya IP Office Application Server 8.1 Avaya Communication Server 1000M Signaling Server 7.6 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.6 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.6 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.6 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya CMS r17 Avaya Aura System Platform 6.2.1 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform SP1.1 Avaya Aura System Platform 6.3 Avaya Aura System Platform 6.2.1.0.9 Avaya Aura System Platform 6.2 SP1 Avaya Aura System Platform 6.2 Avaya Aura System Platform 6.0.3.9.3 Avaya Aura System Platform 6.0.3.8.3 Avaya Aura System Platform 6.0.3.0.3 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.3.2 Avaya Aura System Manager 6.3.1 Avaya Aura System Manager 6.3 Avaya Aura System Manager 6.2.3 Avaya Aura System Manager 6.2 SP3 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura System Manager 5.0 Avaya Aura Session Manager 6.3.1 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.5 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.0.1 Avaya Aura Session Manager 6.3 Avaya Aura Session Manager 6.2.3 Avaya Aura Session Manager 6.2.2 Avaya Aura Session Manager 6.2 SP1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0.2 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2.4 Avaya Aura Session Manager 5.2.1 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 5.0 Avaya Aura Session Manager 1.1.1 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Avaya Aura Presence Services 6.1.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.2 Avaya Aura Presence Services 6.1 SP2 Avaya Aura Presence Services 6.1 SP1 Avaya Aura Presence Services 6.1 Avaya Aura Messaging 6.1.1 Avaya Aura Messaging 6.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 6.0 SP2 Avaya Aura Experience Portal 6.0 SP1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 7.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.3 Avaya Aura Communication Manager Utility Services 6.2.5.0.15 Avaya Aura Communication Manager Utility Services 6.2.4.0.15 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 SP 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.2 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Server 5300 SIP Core 3.0 PB3 Avaya Aura Application Server 5300 SIP Core 3.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 PB28 Avaya Aura Application Server 5300 SIP Core 2.0 PB26 Avaya Aura Application Server 5300 SIP Core 2.0 PB25 Avaya Aura Application Server 5300 SIP Core 2.0 PB23 Avaya Aura Application Server 5300 SIP Core 2.0 PB19 Avaya Aura Application Server 5300 SIP Core 2.0 PB16 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.2 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 6.0 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Avaya Aura Application Enablement Services 5.0 Avaya 96x1 IP Deskphones 6.2 Apple Mac OS X 10.8.5 |
| Not Vulnerable: |
Oracle Solaris 11.1.7.5.0 Juniper CTPOS 7.1r2 Juniper CTPOS 7.1r1 EMC VPLEX GeoSynchrony 5.3 Apple Mac OS X 10.9 |
Discussion
Perl CVE-2013-1667 Input Rehashing Denial of Service Vulnerability
Perl is prone to a denial-of-service vulnerability.
Successful exploits will allow attackers to cause a denial-of-service conditions.
Perl versions 5.8.2 through 5.16.x are vulnerable.
Perl is prone to a denial-of-service vulnerability.
Successful exploits will allow attackers to cause a denial-of-service conditions.
Perl versions 5.8.2 through 5.16.x are vulnerable.
Exploit / POC
Perl CVE-2013-1667 Input Rehashing Denial of Service Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Perl CVE-2013-1667 Input Rehashing Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Slackware Linux 13.1
Slackware Linux x86_64 -current
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Slackware Linux 13.1
-
Slackware perl-5.10.1-i486-2_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ perl-5.10.1-i486-2_slack13.1.txz
Slackware Linux x86_64 -current
-
Slackware perl-5.16.3-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ d/perl-5.16.3-x86_64-1.txz
References
Perl CVE-2013-1667 Input Rehashing Denial of Service Vulnerability
References:
References:
- CVE-2013-1667 Denial of Service (DoS) vulnerability in Perl (Oracle)
- CVE-2013-1667 Denial of Service (DoS) vulnerability in Perl 5.12 (Oracle)
- CVE-2013-1667 Denial of Service (DoS) vulnerability in Perl 5.16 (Oracle)
- CVE-2013-1667: important rehashing flaw (Perl)
- ESA-2014-016: EMC VPLEX Multiple Vulnerabilities (EMC)
- IV43973: PERL CVE-2012-5526 & CVE-2013-1667 VULNERABILITY (IBM)
- Perl Homepage (Perl)
- Security vulnerabilities in Perl for AIX (IBM)
- 2016-04 Security Bulletin: CTP Series: Multiple vulnerabilities in CTP Series (Juniper)
- ASA-2013-277: perl security update (RHSA-2013-0685) (Avaya)
- ASA-2013-360: Wind River Linux perl Security Update (WIND00413550 WIND00397027) (Avaya)
- HPSBUX02928 SSRT101274 rev.1 - HP-UX running perl, Remote Denial of Service (DoS (HP)
- Oracle VM Server for x86 Bulletin - July 2016 (Oracle)
- USN-1770-1: Perl vulnerability (Ubuntu)
- Xerox Security Bulletin XRX13-007 (Xerox)