CVE-2020-12723

r

egcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.

References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html Mailing List Third Party Advisory
https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod Third Party Advisory
https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3 Patch Third Party Advisory
https://github.com/Perl/perl5/issues/16947 Third Party Advisory
https://github.com/Perl/perl5/issues/17743 Third Party Advisory
https://github.com/perl/perl5/commit/66bbb51b93253a3f87d11c2695cfb7bdb782184a Patch Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/
https://security.gentoo.org/glsa/202006-03 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200611-0001/ Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Patch Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html Mailing List Third Party Advisory
https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod Third Party Advisory
https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3 Patch Third Party Advisory
https://github.com/Perl/perl5/issues/16947 Third Party Advisory
https://github.com/Perl/perl5/issues/17743 Third Party Advisory
https://github.com/perl/perl5/commit/66bbb51b93253a3f87d11c2695cfb7bdb782184a Patch Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/
https://security.gentoo.org/glsa/202006-03 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200611-0001/ Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Patch Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_eagle_application_processor:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:10.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:10.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_lsms:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:configuration_manager:12.1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:sd-wan_edge:8.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:sd-wan_edge:9.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:tekelec_platform_distribution:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:00

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html - Mailing List, Third Party Advisory
References () https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod - Third Party Advisory () https://github.com/Perl/perl5/blob/blead/pod/perl5303delta.pod - Third Party Advisory
References () https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3 - Patch, Third Party Advisory () https://github.com/Perl/perl5/compare/v5.30.2...v5.30.3 - Patch, Third Party Advisory
References () https://github.com/Perl/perl5/issues/16947 - Third Party Advisory () https://github.com/Perl/perl5/issues/16947 - Third Party Advisory
References () https://github.com/Perl/perl5/issues/17743 - Third Party Advisory () https://github.com/Perl/perl5/issues/17743 - Third Party Advisory
References () https://github.com/perl/perl5/commit/66bbb51b93253a3f87d11c2695cfb7bdb782184a - Patch, Third Party Advisory () https://github.com/perl/perl5/commit/66bbb51b93253a3f87d11c2695cfb7bdb782184a - Patch, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE/ -
References () https://security.gentoo.org/glsa/202006-03 - Third Party Advisory () https://security.gentoo.org/glsa/202006-03 - Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20200611-0001/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20200611-0001/ - Third Party Advisory
References () https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory () https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuApr2021.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpuApr2021.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpujan2021.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpujan2021.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpujan2022.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpujan2022.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuoct2020.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpuoct2020.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuoct2021.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpuoct2021.html - Patch, Third Party Advisory