First published: Fri Sep 15 2017(Updated: )
Perl. Public CVE-2017-12837 was addressed by updating the function in Perl 5.18
Credit: Jakub Wilk cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Perl Perl | <=5.24.2 | |
Perl Perl | =5.26.0 | |
Apple macOS High Sierra | <10.13.2 | 10.13.2 |
Apple Sierra | ||
Apple El Capitan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-12837 is a heap-based buffer overflow vulnerability in the S_regatom function in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1.
CVE-2017-12837 allows remote attackers to cause a denial of service (out-of-bounds write) in Perl by using a regular expression with a '\N{}' escape and the case-insensitive modifier.
Perl versions up to and including 5.24.2 and 5.26.0 are affected by CVE-2017-12837.
CVE-2017-12837 has a severity rating of 7.5 (high).
To mitigate CVE-2017-12837, update Perl to version 5.24.3-RC1 or later for Perl 5.24.x, or version 5.26.1-RC1 or later for Perl 5.26.x.