CVE-2018-12558: High severity email\ \ vulnerability
Published Jun 19, 2018
·Updated
The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").
Affected Software
3 affected componentsFixes available
debian/libemail-address-perl<=1.908-1, <=1.909-1
1.908-1+deb9u11.912-1
debian/libemail-address-perl
1.912-11.913-1
Email\ \<=1.909
Event History
Jun 20, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12558?
CVE-2018-12558 has a medium severity level due to the potential for Denial of Service through algorithmic complexity.
2
How do I fix CVE-2018-12558?
To fix CVE-2018-12558, you should upgrade to libemail-address-perl version 1.912-1 or later.
3
What versions are affected by CVE-2018-12558?
Affected versions of libemail-address-perl include those up to and including 1.909.
4
Is CVE-2018-12558 a remote attack vulnerability?
CVE-2018-12558 can be exploited through specially crafted inputs, making it possible to cause a Denial of Service remotely.
5
What module is impacted by CVE-2018-12558?
CVE-2018-12558 impacts the Email::Address module of Perl.