First published: Mon Nov 05 2018(Updated: )
A flaw was found in Perl versions 5.22 through 5.26. Heap-buffer-overflow read in regcomp.c Upstream Patch: <a href="https://github.com/Perl/perl5/commit/43b2f4ef399e2fd7240b4eeb0658686ad95f8e62">https://github.com/Perl/perl5/commit/43b2f4ef399e2fd7240b4eeb0658686ad95f8e62</a>
Credit: Jakub Wilk Jayakrishna Menon Eiichi Tsukata cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Mojave | <10.14.4 | 10.14.4 |
Apple High Sierra | ||
Apple Sierra | ||
redhat/perl | <5.26.3 | 5.26.3 |
redhat/perl | <5.28.1 | 5.28.1 |
Perl Perl | <5.26.3 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Debian Debian Linux | =9.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =7.4 | |
Redhat Enterprise Linux | =7.5 | |
Redhat Enterprise Linux | =7.6 | |
NetApp E-Series SANtricity OS Controller | >=11.0<=11.40 | |
NetApp Snap Creator Framework | ||
Netapp Snapcenter | ||
Netapp Snapdrive Unix | ||
Apple Mac OS X | <10.14.4 | |
debian/perl | 5.32.1-4+deb11u3 5.32.1-4+deb11u4 5.36.0-7+deb12u1 5.40.0-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-18313 is a vulnerability in Perl that allows for a buffer over-read which can lead to disclosure of sensitive information.
CVE-2018-18313 has a severity score of 9.1, which is considered critical.
Perl versions before 5.26.3 are affected by CVE-2018-18313.
To fix CVE-2018-18313, upgrade Perl to version 5.26.3 or later.
You can find more information about CVE-2018-18313 at the following references: [Link 1](http://seclists.org/fulldisclosure/2019/Mar/49), [Link 2](http://www.securitytracker.com/id/1042181), [Link 3](https://access.redhat.com/errata/RHSA-2019:0001).