Heap-based buffer over-read in Perl - CVE-2018-6798
Published: April 16, 2018 / Updated: April 16, 2018
Vulnerability identifier: #VU11834
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6798
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information or execute arbitrary code on the target system.
The weakness exists due to heap-based buffer over-read. A local attacker can exploit a specially crafted locale dependent regular expression, trigger memory corruption and gain access to potentially sensitive information or run Perl code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to heap-based buffer over-read. A local attacker can exploit a specially crafted locale dependent regular expression, trigger memory corruption and gain access to potentially sensitive information or run Perl code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Perl
Debian Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for x86_64
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Development Tools Module
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
Fedora
perl (Alpine package)
perl
perl-32bit-debuginfo
perl-base
perl-debuginfo
perl-base-debuginfo
perl-debugsource
perl-base-32bit-debuginfo
perl-base-32bit
perl-doc
perl-base-64bit
perl-core-DB_File-64bit
perl-64bit-debuginfo
perl-64bit
perl-base-64bit-debuginfo
perl-core-DB_File-64bit-debuginfo
perl-32bit
perl-core-DB_File-32bit-debuginfo
perl-core-DB_File
perl-core-DB_File-debuginfo
perl-core-DB_File-32bit
perl-Module-CoreList
RSA Authentication Manager
PowerStore X
PowerStore T
Storage Resource Manager
EMC Cloud Tiering Appliance
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
Debian Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for x86_64
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Development Tools Module
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
Fedora
perl (Alpine package)
perl
perl-32bit-debuginfo
perl-base
perl-debuginfo
perl-base-debuginfo
perl-debugsource
perl-base-32bit-debuginfo
perl-base-32bit
perl-doc
perl-base-64bit
perl-core-DB_File-64bit
perl-64bit-debuginfo
perl-64bit
perl-base-64bit-debuginfo
perl-core-DB_File-64bit-debuginfo
perl-32bit
perl-core-DB_File-32bit-debuginfo
perl-core-DB_File
perl-core-DB_File-debuginfo
perl-core-DB_File-32bit
perl-Module-CoreList
RSA Authentication Manager
PowerStore X
PowerStore T
Storage Resource Manager
EMC Cloud Tiering Appliance
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
How to mitigate CVE-2018-6798
Update to version 5.26.2.
perl (Alpine package) - update to 5.24.4-r0
RSA Authentication Manager - update to 8.7 SP2 Patch 4
PowerStore X - update to 3.2.1.4-2386214
PowerStore T - update to 4.0.0.2-2365061
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
perl - addressed in versions 5.24.4-397.fc26, 5.26.2-404.fc27, 5.26.2-410.fc28
perl-32bit-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-debugsource - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base-32bit-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base-32bit - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-doc - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base-64bit - update to 5.26.1-150300.17.17.1
perl-core-DB_File-64bit - update to 5.26.1-150300.17.17.1
perl-64bit-debuginfo - update to 5.26.1-150300.17.17.1
perl-64bit - update to 5.26.1-150300.17.17.1
perl-base-64bit-debuginfo - update to 5.26.1-150300.17.17.1
perl-core-DB_File-64bit-debuginfo - update to 5.26.1-150300.17.17.1
perl-32bit - update to 5.26.1-150300.17.17.1
perl-core-DB_File-32bit-debuginfo - update to 5.26.1-150300.17.17.1
perl-core-DB_File - update to 5.26.1-150300.17.17.1
perl-core-DB_File-debuginfo - update to 5.26.1-150300.17.17.1
perl-core-DB_File-32bit - update to 5.26.1-150300.17.17.1
perl-Module-CoreList - addressed in versions 5.20180414-1.fc26, 5.20180414-1.fc27
Dell EMC VxRail Appliance - update to 8.0.213
EMC Cloud Tiering Appliance - update to 13.2.0.2.31
RSA Authentication Manager - update to 8.7 SP2 Patch 4
PowerStore X - update to 3.2.1.4-2386214
PowerStore T - update to 4.0.0.2-2365061
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
perl - addressed in versions 5.24.4-397.fc26, 5.26.2-404.fc27, 5.26.2-410.fc28
perl-32bit-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-debugsource - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base-32bit-debuginfo - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base-32bit - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-doc - addressed in versions 5.26.1-150000.7.18.1, 5.26.1-150300.17.17.1
perl-base-64bit - update to 5.26.1-150300.17.17.1
perl-core-DB_File-64bit - update to 5.26.1-150300.17.17.1
perl-64bit-debuginfo - update to 5.26.1-150300.17.17.1
perl-64bit - update to 5.26.1-150300.17.17.1
perl-base-64bit-debuginfo - update to 5.26.1-150300.17.17.1
perl-core-DB_File-64bit-debuginfo - update to 5.26.1-150300.17.17.1
perl-32bit - update to 5.26.1-150300.17.17.1
perl-core-DB_File-32bit-debuginfo - update to 5.26.1-150300.17.17.1
perl-core-DB_File - update to 5.26.1-150300.17.17.1
perl-core-DB_File-debuginfo - update to 5.26.1-150300.17.17.1
perl-core-DB_File-32bit - update to 5.26.1-150300.17.17.1
perl-Module-CoreList - addressed in versions 5.20180414-1.fc26, 5.20180414-1.fc27
Dell EMC VxRail Appliance - update to 8.0.213
EMC Cloud Tiering Appliance - update to 13.2.0.2.31
External References
Related Security Bulletins
- Debian update for perl
- Red Hat update for perl
- Gentoo update for Perl
- Heap-based buffer over-read in perl (Alpine package)
- SUSE update for perl
- SUSE update for perl
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell PowerStore X
- Multiple vulnerabilities in Dell PowerStore T Family
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Fedora 28 update for perl
- Fedora 27 update for perl, perl-Module-CoreList
- Fedora 26 update for perl, perl-Module-CoreList
- RSA Authentication Manager update for third-party components