CVE-2017-12814: Buffer Overflow
Published Sep 27, 2017
·Updated
Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable.
Affected Software
3 affected components
Perl Perl<=5.24.2
Perl Perl=5.26.0
Microsoft Windows
Remediation
Patch Available
Event History
Sep 27, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12814?
CVE-2017-12814 has a high severity due to its potential for allowing arbitrary code execution.
2
How do I fix CVE-2017-12814?
To fix CVE-2017-12814, upgrade Perl to version 5.24.3-RC1 or 5.26.1-RC1 or later.
3
What specific versions of Perl are affected by CVE-2017-12814?
CVE-2017-12814 affects Perl versions before 5.24.3-RC1 and 5.26.x versions before 5.26.1-RC1.
4
What are the consequences of exploiting CVE-2017-12814?
Exploiting CVE-2017-12814 can lead to arbitrary code execution on vulnerable Windows systems running affected Perl versions.
5
Is CVE-2017-12814 a Cross-Site Scripting (XSS) vulnerability?
No, CVE-2017-12814 is a stack-based buffer overflow vulnerability, not an XSS vulnerability.