A heap buffer overflow vulnerability was discovered in...
High severity
Unreviewed
Published
Apr 13, 2025
to the GitHub Advisory Database
•
Updated Apr 30, 2025
Description
Published by the National Vulnerability Database
Apr 13, 2025
Published to the GitHub Advisory Database
Apr 13, 2025
Last updated
Apr 30, 2025
A heap buffer overflow vulnerability was discovered in Perl.
When there are non-ASCII bytes in the left-hand-side of the
tr
operator,S_do_trans_invmap
can overflow the destination pointerd
.$ perl -e '$_ = "\x{FF}" x 1000000; tr/\xFF/\x{100}/;'
Segmentation fault (core dumped)
It is believed that this vulnerability can enable Denial of Service and possibly Code Execution attacks on platforms that lack sufficient defenses.
References