CVE-2018-18314

Source
https://cve.org/CVERecord?id=CVE-2018-18314
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-18314.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-18314
Downstream
Related
Published
2018-12-07T21:29:00.920Z
Modified
2026-04-11T18:19:58.288602Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "introduced": "11.0"
                },
                {
                    "last_affected": "11.40"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "14.04"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "16.04"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "18.04"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "18.10"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "9.0"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "6.0"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.4"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:redhat:enterprise_linux:7.5:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.5"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:o:redhat:enterprise_linux:7.6:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.6"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/perl/perl5

Affected ranges

Type
GIT
Repo
https://github.com/perl/perl5
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": [
        "CPE_FIELD",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.26.3"
        }
    ]
}

Affected versions

Other
GitLive-blead
perl-5a2
perl-5a9
if-0.*
if-0.0603
if-0.0604
if-0.0605
perl-1.*
perl-1.0
perl-2.*
perl-2.0
perl-3.*
perl-3.000
perl-3.044
perl-4.*
perl-4.0.00
perl-4.0.36
perl-5.*
perl-5.000
perl-5.000o
perl-5.001
perl-5.001n
perl-5.002
perl-5.002_01
perl-5.003
perl-5.005
perl-5.6.0
perl-5.7.0
perl-5.7.1
perl-5.7.2
perl-5.7.3
perl-5.8.0
perl-5.9.0
perl-5.9.1
perl-5.9.2
perl-5.9.3
perl-5.9.4
perl-5.9.5
v5.*
v5.10.0
v5.11.0
v5.11.1
v5.11.3
v5.11.4
v5.11.5
v5.12.0
v5.12.0-RC0
v5.12.0-RC1
v5.12.0-RC2
v5.12.0-RC3
v5.12.0-RC4
v5.12.0-RC5
v5.13.0
v5.13.1
v5.13.10
v5.13.11
v5.13.2
v5.13.3
v5.13.4
v5.13.5
v5.13.6
v5.13.7
v5.13.8
v5.13.9
v5.14.0
v5.14.0-RC1
v5.14.0-RC2
v5.14.0-RC3
v5.15.0
v5.15.1
v5.15.2
v5.15.3
v5.15.4
v5.15.5
v5.15.9
v5.16.0
v5.16.0-RC1
v5.16.0-RC2
v5.17.0
v5.17.2
v5.17.4
v5.17.6
v5.17.7
v5.17.7.0
v5.17.8
v5.17.9
v5.18.0
v5.18.0-RC1
v5.18.0-RC2
v5.18.0-RC3
v5.18.0-RC4
v5.19.0
v5.19.1
v5.19.11
v5.19.2
v5.19.3
v5.19.5
v5.19.7
v5.20.0
v5.20.0-RC1
v5.21.0
v5.21.1
v5.21.10
v5.21.11
v5.21.4
v5.21.5
v5.21.6
v5.21.8
v5.21.9
v5.22.0
v5.22.0-RC1
v5.22.0-RC2
v5.23.0
v5.23.1
v5.23.2
v5.23.3
v5.23.4
v5.23.6
v5.23.7
v5.24.0
v5.24.0-RC1
v5.24.0-RC2
v5.24.0-RC3
v5.24.0-RC4
v5.24.0-RC5
v5.25.0
v5.25.11
v5.25.2
v5.25.3
v5.25.4
v5.25.5
v5.25.7
v5.25.9
v5.26.0
v5.26.0-RC2
v5.26.1
v5.26.1-RC1
v5.26.2
v5.26.2-RC1
v5.26.3-RC1
v5.27.0
v5.27.3
v5.27.5
v5.27.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-18314.json"
vanir_signatures_modified
"2026-04-11T18:19:58Z"
vanir_signatures
[
    {
        "source": "https://github.com/perl/perl5/commit/19a498a461d7c81ae3507c450953d1148efecf4f",
        "digest": {
            "line_hashes": [
                "223268628462856602148935175873755215617",
                "313408353012981534493045917185127835857",
                "266127827055078324384802249770660112339",
                "285836914655491125682420966729039477494",
                "104196031833061798077686775585221850946",
                "248293360698196579463078778875811611316",
                "15122577617569625529562997538534393873",
                "308823104604911808145452185928224313419",
                "203800263514158027825725019238873477026",
                "107466311482147865604050218240859408984",
                "177874573294719735042442008112168038785",
                "77403613722849491357760194387364943383",
                "102119391447246124210913313777767367456",
                "226691513493903448915856763334131526968",
                "170203151658750574904400503411948311754",
                "265292750699339053776113847266736449027",
                "288481162027090262443534171369455598745",
                "271106562193067536550176696803511691641",
                "178445048125630411538440887249612166081",
                "13568361151856466286152983320767666317",
                "304141175679598219286807521158297346817",
                "60562298620849427187765097732677509389",
                "55904387004558794324485484099908358082",
                "211622532022823162120141239412509457147",
                "317277725681055604407052642473703422121",
                "226142453573830261875302305410550161427",
                "32977240991188030081375511742418347020",
                "226388354892905955488671524671965892761",
                "233012581692882530300754013088815660848"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "regcomp.c"
        },
        "deprecated": false,
        "id": "CVE-2018-18314-a8c65bda",
        "signature_version": "v1",
        "signature_type": "Line"
    }
]