CVE-2017-12837

Description

Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a N{} escape and the case-insensitive modifier.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
2.585

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2 Combo UpdateMac
Practical Extraction and Report Language (USN-2916-1) perl_5.18.2-2ubuntu1.3_i386.debLinux
Practical Extraction and Report Language (USN-2916-1) perl_5.18.2-2ubuntu1.3_amd64.debLinux
Practical Extraction and Report Language (USN-3478-1) perl_5.18.2-2ubuntu1.3_i386.debLinux
Practical Extraction and Report Language (USN-3478-1) perl_5.18.2-2ubuntu1.3_amd64.debLinux
Practical Extraction and Report Language (USN-3478-1) perl_5.22.1-9ubuntu0.2_i386.debLinux
Practical Extraction and Report Language (USN-3478-1) perl_5.22.1-9ubuntu0.2_amd64.debLinux
Practical Extraction and Report Language (USN-3478-1) perl_5.24.1-2ubuntu1.1_i386.debLinux
Practical Extraction and Report Language (USN-3478-1) perl_5.24.1-2ubuntu1.1_amd64.debLinux
perl security update(DSA-3982-1) perl_5.24.1-3+deb9u1_i386.debLinux
SUSE-SU-2017:3092-1(SUSE Linux Enterprise Desktop 12-SP2 ) perl-5.18.2-12.3.1.x86_64.rpmLinux
SUSE-SU-2017:3092-1(SUSE Linux Enterprise Desktop 12-SP2 ) perl-32bit-5.18.2-12.3.1.x86_64.rpmLinux
SUSE-SU-2017:3092-1(SUSE Linux Enterprise Desktop 12-SP2 ) perl-base-5.18.2-12.3.1.x86_64.rpmLinux
SUSE-SU-2017:3092-1(SUSE Linux Enterprise Desktop 12-SP2 ) perl-base-debuginfo-5.18.2-12.3.1.x86_64.rpmLinux
SUSE-SU-2017:3092-1(SUSE Linux Enterprise Desktop 12-SP2 ) perl-debuginfo-5.18.2-12.3.1.x86_64.rpmLinux
SUSE-SU-2017:3092-1(SUSE Linux Enterprise Desktop 12-SP2 ) perl-debuginfo-32bit-5.18.2-12.3.1.x86_64.rpmLinux
SUSE-SU-2017:3092-1(SUSE Linux Enterprise Desktop 12-SP2 ) perl-debugsource-5.18.2-12.3.1.x86_64.rpmLinux
SUSE-SU-2017:3092-1(SUSE Linux Enterprise Desktop 12-SP2 ) perl-doc-5.18.2-12.3.1.noarch.rpmLinux
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2017-12837)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234