bugs.debian.org
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628836 CVE-2010-4777
Perl 5.x - 'Perl_reg_numbered_buff_fetch()' Remote Denial of Service
Record summary
CVE-2010-4777 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debugging enabled, allows context-dependent attackers to cause a denial of service (assertion failure and application exit) via crafted input that is not properly handled when using certain regular expressions, as demonstrated by causing SpamAssassin and OCSInventory to crash.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPerl 5.x - 'Perl_reg_numbered_buff_fetch()' Remote Denial of ServiceExploitDB exploitby Vladimir PerepelitsaNot analyzed1 file
References
8forums.ocsinventory-ng.org
http://forums.ocsinventory-ng.org/viewtopic.php?id=7215 SUSE-SR:2011:009Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html openSUSE-SU-2011:0479Vendor advisory
http://lists.opensuse.org/opensuse-updates/2011-05/msg00025.html bugzilla.redhat.com
https://bugzilla.redhat.com/show_bug.cgi?id=694166 [Postfixbuch-users] 20110222 proxy-reject: END-OF-MESSAGE: 451 4.3.0 Error: queue file write errormailing list
https://listi.jpberlin.de/pipermail/postfixbuch-users/2011-February/055885.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-4777 rt.perl.orgConfirmation
https://rt.perl.org/Public/Bug/Display.html?id=76538