← All CVEs

CVE-2020-10543

high · 8.2

Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.

8.2
CVSS
11.3%
EPSS (exploit prob.)
96th
EPSS percentile
2020-06-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Weaknesses

CWE-190CWE-787

Affected products

VendorProductAffected versions
perlperl< 5.30.3
fedoraprojectfedora31
opensuseleap15.1
oraclecommunications_billing_and_revenue_management12.0.0.2.0
oraclecommunications_billing_and_revenue_management12.0.0.3.0
oraclecommunications_diameter_signaling_router>= 8.0.0, <= 8.5.0
oraclecommunications_eagle_application_processor>= 16.1.0, <= 16.4.0
oraclecommunications_eagle_lnp_application_processor10.1
oraclecommunications_eagle_lnp_application_processor10.2
oraclecommunications_eagle_lnp_application_processor46.7
oraclecommunications_eagle_lnp_application_processor46.8
oraclecommunications_eagle_lnp_application_processor46.9
oraclecommunications_lsms>= 13.1, <= 13.4
oraclecommunications_offline_mediation_controller12.0.0.3.0
oraclecommunications_performance_intelligence_center>= 10.3.0.0.0, <= 10.3.0.2.1
oraclecommunications_performance_intelligence_center>= 10.4.0.1.0, <= 10.4.0.3.1
oraclecommunications_pricing_design_center12.0.0.3.0
oracleconfiguration_manager12.1.2.0.8
oracleenterprise_manager_base_platform13.4.0.0
oraclesd-wan_edge8.2
oraclesd-wan_edge9.0
oraclesd-wan_edge9.1
oracletekelec_platform_distribution>= 7.4.0, <= 7.7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-10543