CVE-2017-12837

Priority
Medium
Description
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5
before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to
cause a denial of service (out-of-bounds write) via a regular expression
with a '\N{}' escape and the case-insensitive modifier.
References
Bugs
Notes
 leosilva> portion of affected code is quite different in precise, needs triage
 leosilva> could not reproduce in precise.
Assigned-to
leosilva
Package
Source: perl (LP Ubuntu Debian)
Upstream:released (5.26.0-8)
Ubuntu 17.10 (Artful Aardvark):not-affected (5.26.0-8ubuntu1)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (5.26.0-8ubuntu1)
Ubuntu 12.04 ESM (Precise Pangolin):not-affected (code not present)
Ubuntu 14.04 LTS (Trusty Tahr):released (5.18.2-2ubuntu1.3)
Ubuntu 16.04 LTS (Xenial Xerus):released (5.22.1-9ubuntu0.2)
Ubuntu 17.04 (Zesty Zapus):released (5.24.1-2ubuntu1.1)
Patches:
Upstream:https://perl5.git.perl.org/perl.git/commitdiff/96c83ed78aeea1a0496dd2b2d935869a822dc8a5
More Information

Updated: 2017-11-13 14:14:14 UTC (commit 13674)