Input validation error - CVE-2018-12558
Published: June 20, 2018 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("f").
Affected software
Opensuse
SUSE Linux
perl-email-address (Alpine package)
WordPress Gallery Plugin - NextGEN Gallery
How to mitigate CVE-2018-12558
WordPress Gallery Plugin - NextGEN Gallery - update to 0.92