Vulnerability Intelligence Report
CVE-2020-10878
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
No Active Exploit Signals
CVSS Base Score
8.6
HIGH
EPSS Probability:4.88%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| perl | perl | all |
| fedoraproject | fedora | 31 |
| opensuse | leap | 15.1 |
| netapp | oncommand_workflow_automation | all |
| netapp | snap_creator_framework | all |
| oracle | communications_billing_and_revenue_management | 12.0.0.2.0, 12.0.0.3.0 |
| oracle | communications_diameter_signaling_router | all |
| oracle | communications_eagle_application_processor | all |
| oracle | communications_eagle_lnp_application_processor | 10.1, 10.2, 46.7, 46.8, 46.9 |
| oracle | communications_lsms | all |
| oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
| oracle | communications_performance_intelligence_center | all |
| oracle | communications_pricing_design_center | 12.0.0.3.0 |
| oracle | configuration_manager | 12.1.2.0.8 |
| oracle | enterprise_manager_base_platform | 13.4.0.0 |
| oracle | sd-wan_aware | 8.2, 9.0, 9.1 |
| oracle | tekelec_platform_distribution | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
4.879%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2020-03-23T00:00:00 |
| Published | 2020-06-05T13:27:22 |
| Last Updated | 2024-08-04T11:14:15 |
Community Chatter & Buzz