CVE-2013-7422

macOS < 10.10.4 - Remote Code Execution via Perl regcomp.c Integer Underflow

Title source: manual
STIX 2.1

Description

Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201507-11
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2916-1
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT205031
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75704

Scores

EPSS 0.0305
EPSS Percentile 86.2%

Details

CWE
CWE-189
Status published
Products (2)
apple/mac_os_x < 10.10.4
perl/perl 5.18.4
Published Aug 16, 2015
Tracked Since Feb 18, 2026