Vulnerability Intelligence Report
CVE-2020-12723
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:5.97%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| perl | perl | all |
| netapp | oncommand_workflow_automation | all |
| netapp | snap_creator_framework | all |
| fedoraproject | fedora | 31 |
| opensuse | leap | 15.1 |
| oracle | communications_billing_and_revenue_management | 12.0.0.2.0, 12.0.0.3.0 |
| oracle | communications_diameter_signaling_router | all |
| oracle | communications_eagle_application_processor | all |
| oracle | communications_eagle_lnp_application_processor | 10.1, 10.2 |
| oracle | communications_lsms | all |
| oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
| oracle | communications_performance_intelligence_center | all |
| oracle | configuration_manager | 12.1.2.0.8 |
| oracle | enterprise_manager_base_platform | 13.4.0.0 |
| oracle | sd-wan_edge | 8.2, 9.0, 9.1 |
| oracle | tekelec_platform_distribution | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
5.971%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2020-05-08T00:00:00 |
| Published | 2020-06-05T14:20:50 |
| Last Updated | 2024-08-04T12:04:22 |
Community Chatter & Buzz