CVE-2007-5116
perl - arbitrary code execution
EPSS 4.8%
描述
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.
如何修補 CVE-2007-5116
要修補 CVE-2007-5116,請將受影響套件升級到下列已修補版本。
- Debian/perl—升級至 5.8.8-12 或更新版本
- Debian/perl—升級至 5.8.4-8sarge6 或更新版本
- Debian/perl—升級至 5.8.8-11.1+lenny1 或更新版本
CVE-2007-5116 正在被利用嗎?
低 — EPSS 為 4.8%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 5.8.8-12
- from 0, < 5.8.4-8sarge6
- from 0, < 5.8.8-11.1+lenny1