MGASA-2018-0241

Source
https://advisories.mageia.org/MGASA-2018-0241.html
Import Source
https://advisories.mageia.org/MGASA-2018-0241.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2018-0241
Related
Published
2018-05-16T08:24:56Z
Modified
2018-05-16T07:41:55Z
Summary
Updated perl packages fix security vulnerabilities
Details

Brian Carpenter reported that a crafted regular expression could cause a heap buffer write overflow, with control over the bytes written (CVE-2018-6797).

Nguyen Duc Manh reported that matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure (CVE-2018-6798).

GwanYeong Kim reported that 'pack()' could cause a heap buffer write overflow with a large item count (CVE-2018-6913).

References
Credits

Affected packages

Mageia:6 / perl

Package

Name
perl
Purl
pkg:rpm/mageia/perl?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.22.3-3.2.mga6

Ecosystem specific

{
    "section": "core"
}