ZeroHour

CVE-2020-10878

CVSS 3.1
8.6 high
EPSS
5%p92
Published
()
Modified
Description

Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.

Vendors
perlfedoraprojectopensusenetapporacle
Products
perl, fedora, leap, oncommand workflow automation, snap creator framework, communications billing and revenue management, communications diameter signaling router, communications eagle application processor, communications eagle lnp application processor, communications lsms, communications offline mediation controller, communications performance intelligence center
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

In the news

No ingested article mentions this CVE yet.