Vulnerability CVE-2020-10543: Information

Description

Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.

Severity: HIGH (8.2) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Published: June 5, 2020
Modified: Nov. 7, 2023
Error type identifier: CWE-787CWE-190

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
perlsisyphus5.30.3-alt15.38.2-alt0.2ALT-PU-2020-2905-1259030Fixed
perlp105.30.3-alt15.34.0-alt1ALT-PU-2020-2905-1259030Fixed
perlp95.28.3-alt15.28.3-alt1ALT-PU-2020-3414-1261964Fixed
perlc10f15.30.3-alt15.34.0-alt1ALT-PU-2020-2905-1259030Fixed
perlc9f25.28.3-alt15.28.3-alt1ALT-PU-2020-3343-1261994Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:perl:perl:*:*:*:*:*:*:x86:*
      End excliding
      5.30.3

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:10.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:10.2:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:sd-wan_edge:8.2:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.2.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*
      Start including
      8.0.0
      End including
      8.5.0

      cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:tekelec_platform_distribution:*:*:*:*:*:*:*:*
      Start including
      7.4.0
      End including
      7.7.1

      cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:46.7:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:46.8:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:46.9:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_lsms:*:*:*:*:*:*:*:*
      Start including
      13.1
      End including
      13.4

      cpe:2.3:a:oracle:configuration_manager:12.1.2.0.8:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:sd-wan_edge:9.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_eagle_application_processor:*:*:*:*:*:*:*:*
      Start including
      16.1.0
      End including
      16.4.0

      cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*
      Start including
      10.4.0.1.0
      End including
      10.4.0.3.1

      cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*
      Start including
      10.3.0.0.0
      End including
      10.3.0.2.1