Vulnerability Description
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 3.1 |
| Mandrakesoft | Mandrake Linux | 2007 |
| Mandrakesoft | Mandrake Linux Corporate Server | 3.0 |
| Redhat | Enterprise Linux | 3.0 |
| Redhat | Enterprise Linux Desktop | 3.0 |
| Redhat | Linux Advanced Workstation | 2.1 |
| Rpath | Rpath Linux | 1 |
| Larry Wall | Perl | 5.8.0 |
| Mandrakesoft | Mandrake Multi Network Firewall | 2.0 |
| Openpkg | Openpkg | current |
Related Weaknesses (CWE)
References
- ftp://aix.software.ibm.com/aix/efixes/security/README
- http://docs.info.apple.com/article.html?artnum=307179
- http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html
- http://lists.vmware.com/pipermail/security-announce/2008/000002.html
- http://marc.info/?l=bugtraq&m=120352263023774&w=2
- http://secunia.com/advisories/27479
- http://secunia.com/advisories/27515
- http://secunia.com/advisories/27531Vendor Advisory
- http://secunia.com/advisories/27546
- http://secunia.com/advisories/27548
- http://secunia.com/advisories/27570
- http://secunia.com/advisories/27613
- http://secunia.com/advisories/27756
- http://secunia.com/advisories/27936
- http://secunia.com/advisories/28167
FAQ
What is CVE-2007-5116?
CVE-2007-5116 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicod...
How severe is CVE-2007-5116?
CVE-2007-5116 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5116?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Mandrakesoft Mandrake Linux, Mandrakesoft Mandrake Linux Corporate Server, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop.