Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
[ { "signature_type": "Function", "id": "CVE-2020-10543-501f156b", "source": "https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed", "signature_version": "v1", "target": { "function": "S_study_chunk", "file": "regcomp.c" }, "digest": { "function_hash": "188038057978112623465644672548025025841", "length": 39449.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2020-10543-b76d07fc", "source": "https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed", "signature_version": "v1", "target": { "file": "regcomp.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "326227367672465616021991049804010148793", "15134703551330238417109193759520969772", "336883495148109590279206088498136563982" ] }, "deprecated": false } ]