https://seclists.org/oss-sec/2025/q2/50: CVE-2024-56406: Perl 5.34, 5.36, 5.38 and 5.40 avulnerable to a heap buffer overflow when transliterating non-ASCII bytes
Published Apr 13, 2025
·Updated
Affected Software
2 affected components
Perl Perl>=5.41.0<5.41.10
Perl Perl
Frequently Asked Questions
1
What is the severity of CVE-2024-56406?
CVE-2024-56406 is classified as a high-severity vulnerability due to the potential for heap buffer overflow.
2
How do I fix CVE-2024-56406?
To fix CVE-2024-56406, update Perl to a version that is not affected by this vulnerability, ideally 5.41.11 or later.
3
Which versions of Perl are affected by CVE-2024-56406?
CVE-2024-56406 affects Perl versions 5.34, 5.36, 5.38, and 5.40.
4
What type of vulnerability is CVE-2024-56406?
CVE-2024-56406 is a heap buffer overflow vulnerability that occurs during the transliteration of non-ASCII bytes.
5
When was CVE-2024-56406 published?
CVE-2024-56406 was published on April 13, 2025.