Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Out-of-bounds Write. Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
Remediation
Upgrade perl
to version or higher.
References
CVSS Score
8.2
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityLow
-
AvailabilityHigh
- CVE
- CVE-2020-10543
- CWE
- CWE-787
- Snyk ID
- SNYK-DEBIAN9-PERL-570799
- Disclosed
- 05 Jun, 2020
- Published
- 01 Jun, 2020