← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-10878

Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.

No Active Exploit Signals
CVSS Base Score
8.6
HIGH
EPSS Probability:4.88%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
perl perl all
fedoraproject fedora 31
opensuse leap 15.1
netapp oncommand_workflow_automation all
netapp snap_creator_framework all
oracle communications_billing_and_revenue_management 12.0.0.2.0, 12.0.0.3.0
oracle communications_diameter_signaling_router all
oracle communications_eagle_application_processor all
oracle communications_eagle_lnp_application_processor 10.1, 10.2, 46.7, 46.8, 46.9
oracle communications_lsms all
oracle communications_offline_mediation_controller 12.0.0.3.0
oracle communications_performance_intelligence_center all
oracle communications_pricing_design_center 12.0.0.3.0
oracle configuration_manager 12.1.2.0.8
oracle enterprise_manager_base_platform 13.4.0.0
oracle sd-wan_aware 8.2, 9.0, 9.1
oracle tekelec_platform_distribution all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.879%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-03-23T00:00:00
Published2020-06-05T13:27:22
Last Updated2024-08-04T11:14:15

LINK COPIED TO CLIPBOARD