Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "5.30.3"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0.0.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0.0.3.0"
}
]
},
{
"events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.5.0"
}
]
},
{
"events": [
{
"introduced": "16.1.0"
},
{
"last_affected": "16.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "46.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "46.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "46.9"
}
]
},
{
"events": [
{
"introduced": "13.1"
},
{
"last_affected": "13.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0.0.3.0"
}
]
},
{
"events": [
{
"introduced": "10.3.0.0.0"
},
{
"last_affected": "10.3.0.2.1"
}
]
},
{
"events": [
{
"introduced": "10.4.0.1.0"
},
{
"last_affected": "10.4.0.3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0.0.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.1.2.0.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.4.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.1"
}
]
},
{
"events": [
{
"introduced": "7.4.0"
},
{
"last_affected": "7.7.1"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-10543.json"
[
{
"target": {
"file": "regcomp.c",
"function": "S_study_chunk"
},
"id": "CVE-2020-10543-501f156b",
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 39449.0,
"function_hash": "188038057978112623465644672548025025841"
},
"signature_type": "Function",
"source": "https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed"
},
{
"target": {
"file": "regcomp.c"
},
"id": "CVE-2020-10543-b76d07fc",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"326227367672465616021991049804010148793",
"15134703551330238417109193759520969772",
"336883495148109590279206088498136563982"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed"
}
]