CVE-2013-7422
macOS < 10.10.4 - Remote Code Execution via Perl regcomp.c Integer Underflow
Title source: manualDescription
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
References (6)
Core 6
Core References
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
Patch x_refsource_confirm
http://perl5.git.perl.org/perl.git/commit/0c2990d652e985784f095bba4bc356481a66aa06
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201507-11
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2916-1
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT205031
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/75704
Scores
EPSS
0.0305
EPSS Percentile
86.2%
Details
CWE
CWE-189
Status
published
Products (2)
apple/mac_os_x
< 10.10.4
perl/perl
5.18.4
Published
Aug 16, 2015
Tracked Since
Feb 18, 2026