Your submission was sent successfully! Close

CVE-2011-2939

Published: 13 January 2012

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.

Priority

Low

Status

Package Release Status
perl
Launchpad, Ubuntu, Debian
hardy Not vulnerable
(5.8.8-12ubuntu0.5)
lucid
Released (5.10.1-8ubuntu2.2)
maverick Ignored
(reached end-of-life)
natty Ignored
(reached end-of-life)
oneiric Not vulnerable
(5.12.4-4)
precise Not vulnerable
(5.12.4-4)
quantal Not vulnerable
(5.12.4-4)
upstream
Released (5.12.4-4)
Patches:
other: http://perl5.git.perl.org/perl.git/commitdiff/e46d973584785af1f445c4dedbee4243419cb860#patch5
vendor: https://rhn.redhat.com/errata/RHSA-2011-1424.html