CVE-2023-47038

A vulnerability was found in perl. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:perl:perl:5.34.0:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

28 Mar 2024, 14:15

Type Values Removed Values Added
References
  • () https://perldoc.perl.org/perl5382delta#CVE-2023-47038-Write-past-buffer-end-via-illegal-user-defined-Unicode-property -

05 Feb 2024, 07:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNEEWAACXQCEEAKSG7XX2D5YDRWLCIZJ/ -

29 Dec 2023, 22:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.0
v2 : unknown
v3 : 7.8
References () https://access.redhat.com/security/cve/CVE-2023-47038 - () https://access.redhat.com/security/cve/CVE-2023-47038 - Vendor Advisory
References () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056746 - () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056746 - Mailing List, Patch
References () https://bugzilla.redhat.com/show_bug.cgi?id=2249523 - () https://bugzilla.redhat.com/show_bug.cgi?id=2249523 - Issue Tracking
CPE cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:perl:perl:5.34.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
First Time Redhat enterprise Linux
Perl perl
Perl
Redhat
Summary
  • (es) Se encontró una vulnerabilidad en Perl. Este problema ocurre cuando Perl compila una expresión regular manipulada, lo que puede permitir que un atacante controle el desbordamiento de búfer de bytes en un búfer asignado en el almacenamiento dinámico.
CWE CWE-787

18 Dec 2023, 15:04

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 14:15

Updated : 2024-03-28 14:15


NVD link : CVE-2023-47038

Mitre link : CVE-2023-47038

CVE.ORG link : CVE-2023-47038


JSON object : View

Products Affected

redhat

  • enterprise_linux

perl

  • perl
CWE
CWE-787

Out-of-bounds Write

CWE-122

Heap-based Buffer Overflow