← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-18311

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:11.99%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
perl perl all
canonical ubuntu_linux 12.04, 14.04, 16.04, 18.04, 18.10
debian debian_linux 8.0, 9.0
netapp e-series_santricity_os_controller all
netapp snap_creator_framework all
netapp snapcenter all
netapp snapdriver all
redhat openshift_container_platform 3.11
redhat enterprise_linux 6.0, 7.0, 7.4, 7.5, 7.6
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_eus 7.6
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_aus 7.6
redhat enterprise_linux_server_tus 7.6
redhat enterprise_linux_workstation 7.0
apple mac_os_x all
fedoraproject fedora 29
mcafee web_gateway all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
11.990%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2018-10-14T00:00:00
Published2018-12-07T21:00:00
Patch Date2018-11-29
Last Updated2024-08-05T11:08:21

LINK COPIED TO CLIPBOARD