Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
{ "vanir_signatures": [ { "id": "CVE-2018-18311-03a5f7af", "signature_type": "Line", "target": { "file": "util.c" }, "digest": { "line_hashes": [ "278762646846467458220749028302630386693", "312468557747119978232149888737317887481", "161493643322277275457001869997113710198", "63943654176538038665800518437507596469", "119127681495240114184810842066462406217", "296353623599777734216004584012547961258", "329292465809237107923465957351581805798", "231685815720260020200934945771896543007", "178043359333267592176162773375020071429", "237183783672896658833163336710383737165", "250152108054186789770812128784948443612", "213165741231015538985571116828393668584", "319370801703202954217563985177783524508", "329738588468454201620027238060833819704", "314383455144799346142780865009893270760", "123801379219583801958491077506912609356", "98822304097782848954915188387318587459", "71966028249863066924730486223646774984", "235924869402854404509950940347127961505", "56904741803182023061646506821590483013", "34603087930133241378363355428359713696", "135544590023977588920973923720912825129", "257334656051931252101327244517455703467", "205189281332546020698937958583717221794", "284566781044160816925880904132687163231", "49293671174851459557462202680499054488", "282936611618179306955704672491742136335", "35188081188623385928179560303844355424", "323178167614223974339618985719825179357", "227770051973309539615764254246913432760", "264590287610024220661636043986184376159", "30799101164680659213973560467289847539", "273621009362251584277563984863829014714", "23732282762801728803277791934274787462", "274140217903139139305970336732798880537", "113595096881323809552703933403717361115", "147607090647580381413665750363608955621", "89904576321677848069547443359327286432", "211610302220716257581478870691569150871", "322799440874947332372700787068003765999", "120487017185935785522424645892048162280", "1210109423129691442168615330544529791", "330360107058339846493926721672137367812", "334004709386001461208330486823354622959", "250261000308745423778701670392269024960", "175842549026026986810812406029634743851", "73849908381430057173215485562541545956", "251483224424742296371896010847414292954", "170300462639422336973054749143305320663", "215550845120736407961630486036457954122", "274119170000771695150254389561532174435", "165250254494429546184372444911738558090", "22265498109644917814821019236596096416", "230853035943194497847225723510867911094", "160096760090148610203933711539747990196", "24305426286278845320748928919437622618", "10360737222052097615580851996968375620", "49141794748794404104407450701925671967", "170300462639422336973054749143305320663", "215550845120736407961630486036457954122", "274119170000771695150254389561532174435", "49165777930563725616616829732964403532", "178460126831274040021028138488238520464", "278994080232964427766074689965611310706", "201826042647771855853579827731172743400" ], "threshold": 0.9 }, "source": "https://github.com/perl/perl5/commit/34716e2a6ee2af96078d62b065b7785c001194be", "signature_version": "v1", "deprecated": false } ] }