CVE-2018-18311

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

References

http://seclists.org/fulldisclosure/2019/Mar/49

http://www.securityfocus.com/bid/106145

http://www.securitytracker.com/id/1042181

https://access.redhat.com/errata/RHBA-2019:0327

https://access.redhat.com/errata/RHSA-2019:0001

https://access.redhat.com/errata/RHSA-2019:0010

https://access.redhat.com/errata/RHSA-2019:0109

https://access.redhat.com/errata/RHSA-2019:1790

https://access.redhat.com/errata/RHSA-2019:1942

https://access.redhat.com/errata/RHSA-2019:2400

https://bugzilla.redhat.com/show_bug.cgi?id=1646730

https://github.com/Perl/perl5/commit/34716e2a6ee2af96078d62b065b7785c001194be

https://kc.mcafee.com/corporate/index?page=content&id=SB10278

https://lists.debian.org/debian-lts-announce/2018/11/msg00039.html

https://lists.fedoraproject.org/archives/list/[email protected]/message/RWQGEB543QN7SSBRKYJM6PSOC3RLYGSM/

https://metacpan.org/changes/release/SHAY/perl-5.26.3

https://metacpan.org/changes/release/SHAY/perl-5.28.1

https://rt.perl.org/Ticket/Display.html?id=133204

https://seclists.org/bugtraq/2019/Mar/42

https://security.gentoo.org/glsa/201909-01

https://security.netapp.com/advisory/ntap-20190221-0003/

https://support.apple.com/kb/HT209600

https://usn.ubuntu.com/3834-1/

https://usn.ubuntu.com/3834-2/

https://www.debian.org/security/2018/dsa-4347

https://www.oracle.com/security-alerts/cpuapr2020.html

https://www.oracle.com/security-alerts/cpujul2020.html

https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html

Details

Source: MITRE

Published: 2018-12-07

Updated: 2020-08-24

Type: CWE-787

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 4

OR

cpe:2.3:a:netapp:e-series_santricity_os_controller:-:*:*:*:*:*:*:*

cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*

cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*

cpe:2.3:a:netapp:snapdriver:-:*:*:*:*:unix:*:*

Configuration 5

OR

cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:7.5:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

Configuration 6

OR

cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

Configuration 7

OR

cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

Configuration 8

OR

cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*

cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*

cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*

Tenable Plugins

View all (34 total)

IDNameProductFamilySeverity
135679Oracle Enterprise Manager Cloud Control (Apr 2020 CPU)NessusMisc.
critical
128590GLSA-201909-01 : Perl: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
128471SUSE SLED12 / SLES12 Security Update : perl (SUSE-SU-2019:2264-1)NessusSuSE Local Security Checks
critical
127717RHEL 7 : perl (RHSA-2019:2400)NessusRed Hat Local Security Checks
critical
127629RHEL 7 : perl (RHSA-2019:1942)NessusRed Hat Local Security Checks
critical
127242NewStart CGSL CORE 5.04 / MAIN 5.04 : perl Vulnerability (NS-SA-2019-0054)NessusNewStart CGSL Local Security Checks
critical
126845EulerOS 2.0 SP2 : perl (EulerOS-SA-2019-1717)NessusHuawei Local Security Checks
critical
126758RHEL 7 : perl (RHSA-2019:1790)NessusRed Hat Local Security Checks
critical
124967EulerOS Virtualization 3.0.1.0 : perl (EulerOS-SA-2019-1464)NessusHuawei Local Security Checks
critical
124904EulerOS Virtualization for ARM 64 3.0.1.0 : perl (EulerOS-SA-2019-1401)NessusHuawei Local Security Checks
critical
700522macOS 10.14.x < 10.14.4 Multiple VulnerabilitiesNessus Network MonitorOperating System Detection
critical
123707EulerOS Virtualization 2.5.3 : perl (EulerOS-SA-2019-1239)NessusHuawei Local Security Checks
critical
123706EulerOS Virtualization 2.5.4 : perl (EulerOS-SA-2019-1238)NessusHuawei Local Security Checks
critical
123159openSUSE Security Update : perl (openSUSE-2019-1029)NessusSuSE Local Security Checks
critical
123130macOS 10.13.6 Multiple Vulnerabilities (Security Update 2019-002)NessusMacOS X Local Security Checks
critical
123129macOS and Mac OS X Multiple Vulnerabilities (Security Update 2019-002)NessusMacOS X Local Security Checks
critical
123128macOS 10.14.x < 10.14.4 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
123112EulerOS 2.0 SP3 : perl (EulerOS-SA-2019-1099)NessusHuawei Local Security Checks
critical
123088Amazon Linux AMI : perl (ALAS-2019-1180)NessusAmazon Linux Local Security Checks
critical
122923Photon OS 1.0: Perl PHSA-2019-1.0-0212NessusPhotonOS Local Security Checks
critical
122912Photon OS 2.0: Perl PHSA-2019-2.0-0135NessusPhotonOS Local Security Checks
critical
122672Amazon Linux 2 : perl (ALAS-2019-1166)NessusAmazon Linux Local Security Checks
critical
122212EulerOS 2.0 SP5 : perl (EulerOS-SA-2019-1039)NessusHuawei Local Security Checks
critical
121371CentOS 7 : perl (CESA-2019:0109)NessusCentOS Local Security Checks
critical
121326Scientific Linux Security Update : perl on SL7.x x86_64 (20190122)NessusScientific Linux Local Security Checks
critical
121280RHEL 7 : perl (RHSA-2019:0109)NessusRed Hat Local Security Checks
critical
121279Oracle Linux 7 : perl (ELSA-2019-0109)NessusOracle Linux Local Security Checks
critical
120786Fedora 28 : 4:perl (2018-ca03363d57)NessusFedora Local Security Checks
critical
120656Fedora 29 : 4:perl (2018-9dbe983805)NessusFedora Local Security Checks
critical
120189SUSE SLED15 / SLES15 Security Update : perl (SUSE-SU-2018:4187-1)NessusSuSE Local Security Checks
critical
119863openSUSE Security Update : perl (openSUSE-2018-1595)NessusSuSE Local Security Checks
critical
119337Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : perl vulnerabilities (USN-3834-1)NessusUbuntu Local Security Checks
critical
119311Debian DLA-1601-1 : perl security updateNessusDebian Local Security Checks
critical
119290Debian DSA-4347-1 : perl - security updateNessusDebian Local Security Checks
critical