CVE-2020-10878
—CVSS 3.1
8.6 high
EPSS
5%p92
Published
()
Modified
Description
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
- Vendors
- perlfedoraprojectopensusenetapporacle
- Products
- perl, fedora, leap, oncommand workflow automation, snap creator framework, communications billing and revenue management, communications diameter signaling router, communications eagle application processor, communications eagle lnp application processor, communications lsms, communications offline mediation controller, communications performance intelligence center
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.