REDHAT-BUG-912276: Medium severity perl 5.30.0 vulnerability

Published Feb 18, 2013
·
Updated

A denial of service flaw was found in the way Perl's rehashing code implementation (responsible for recalculation of hash keys and redistribution of hash content) used to react on certain user's input. If a Perl language based application accepted untrusted user input as hash keys, an attacker could use this flaw to cause the perl executable to consume excessive amount of memory (a denial of service via memory exhaustion).

References: [1] http://www.nntp.perl.org/group/perl.perl5.porters/2013/03/msg199755.html

Affected Software

1 affected component
Perl Perl

Event History

Feb 18, 2013
Data Sourced
via Red Hat·09:31 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What are the potential impacts of REDHAT-BUG-912276?

The vulnerability can lead to denial of service attacks by destabilizing Perl applications that handle untrusted user input as hash keys.

2

How can I mitigate the risks associated with REDHAT-BUG-912276?

To mitigate the risks, ensure that your Perl applications properly validate and sanitize all user inputs before processing them.

3

What versions of Perl are affected by REDHAT-BUG-912276?

The vulnerability affects versions of Perl that allow untrusted user input in their hashing code implementation.

4

Is there an official patch available for REDHAT-BUG-912276?

Yes, official patches or updates to address REDHAT-BUG-912276 should be obtained from the Perl development team or your package manager.

5

How can I check if my application is vulnerable to REDHAT-BUG-912276?

To check for vulnerabilities, review your application's code for instances where untrusted user input is used as hash keys in Perl.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203