CVE-2018-18311

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-18311
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18311.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-18311
Downstream
Related
Published
2018-12-07T21:29:00Z
Modified
2025-10-21T04:33:26.914201Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

References

Affected packages

Git / github.com/perl/perl5

Affected ranges

Type
GIT
Repo
https://github.com/perl/perl5
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

GitLive-blead
perl-5a2
perl-5a9

if-0.*

if-0.0602
if-0.0603
if-0.0604
if-0.0605

perl-1.*

perl-1.0

perl-2.*

perl-2.0

perl-3.*

perl-3.000
perl-3.044

perl-4.*

perl-4.0.00
perl-4.0.36

perl-5.*

perl-5.000
perl-5.000o
perl-5.001
perl-5.001n
perl-5.002
perl-5.002_01
perl-5.003
perl-5.003_01
perl-5.003_02
perl-5.003_03
perl-5.003_04
perl-5.003_05
perl-5.003_07
perl-5.003_08
perl-5.003_09
perl-5.003_10
perl-5.003_11
perl-5.003_12
perl-5.003_13
perl-5.003_14
perl-5.003_15
perl-5.003_16
perl-5.003_17
perl-5.003_18
perl-5.003_19
perl-5.003_20
perl-5.003_21
perl-5.003_22
perl-5.003_23
perl-5.003_24
perl-5.003_25
perl-5.003_26
perl-5.003_27
perl-5.003_28
perl-5.003_90
perl-5.003_91
perl-5.003_92
perl-5.003_93
perl-5.003_94
perl-5.003_95
perl-5.003_96
perl-5.003_97
perl-5.003_97a
perl-5.003_97b
perl-5.003_97c
perl-5.003_97d
perl-5.003_97e
perl-5.003_97f
perl-5.003_97g
perl-5.003_97h
perl-5.003_97i
perl-5.003_97j
perl-5.003_98
perl-5.003_99
perl-5.003_99a
perl-5.004
perl-5.004_01
perl-5.004_02
perl-5.004_03
perl-5.004_04
perl-5.005
perl-5.005_01
perl-5.005_02
perl-5.6.0
perl-5.7.0
perl-5.7.1
perl-5.7.2
perl-5.7.3
perl-5.8.0
perl-5.9.0
perl-5.9.1
perl-5.9.2
perl-5.9.3
perl-5.9.4
perl-5.9.5

v5.*

v5.10.0
v5.11.0
v5.11.1
v5.11.2
v5.11.3
v5.11.4
v5.11.5
v5.12.0
v5.12.0-RC0
v5.12.0-RC1
v5.12.0-RC2
v5.12.0-RC3
v5.12.0-RC4
v5.12.0-RC5
v5.13.0
v5.13.1
v5.13.10
v5.13.11
v5.13.2
v5.13.3
v5.13.4
v5.13.5
v5.13.6
v5.13.7
v5.13.8
v5.13.9
v5.14.0
v5.14.0-RC1
v5.14.0-RC2
v5.14.0-RC3
v5.15.0
v5.15.1
v5.15.2
v5.15.3
v5.15.4
v5.15.5
v5.15.6
v5.15.7
v5.15.8
v5.15.9
v5.16.0
v5.16.0-RC1
v5.16.0-RC2
v5.17.0
v5.17.1
v5.17.10
v5.17.11
v5.17.2
v5.17.3
v5.17.4
v5.17.5
v5.17.6
v5.17.7
v5.17.7.0
v5.17.8
v5.17.9
v5.18.0
v5.18.0-RC1
v5.18.0-RC2
v5.18.0-RC3
v5.18.0-RC4
v5.19.0
v5.19.1
v5.19.10
v5.19.11
v5.19.2
v5.19.3
v5.19.4
v5.19.5
v5.19.6
v5.19.7
v5.19.8
v5.19.9
v5.20.0
v5.20.0-RC1
v5.21.0
v5.21.1
v5.21.10
v5.21.11
v5.21.2
v5.21.3
v5.21.4
v5.21.5
v5.21.6
v5.21.7
v5.21.8
v5.21.9
v5.22.0
v5.22.0-RC1
v5.22.0-RC2
v5.23.0
v5.23.1
v5.23.2
v5.23.3
v5.23.4
v5.23.5
v5.23.6
v5.23.7
v5.23.8
v5.23.9
v5.24.0
v5.24.0-RC1
v5.24.0-RC2
v5.24.0-RC3
v5.24.0-RC4
v5.24.0-RC5
v5.25.0
v5.25.1
v5.25.10
v5.25.11
v5.25.12
v5.25.2
v5.25.3
v5.25.4
v5.25.5
v5.25.6
v5.25.7
v5.25.8
v5.25.9
v5.26.0
v5.26.0-RC1
v5.26.0-RC2
v5.27.0
v5.27.1
v5.27.10
v5.27.11
v5.27.2
v5.27.3
v5.27.4
v5.27.5
v5.27.6
v5.27.7
v5.27.8
v5.27.9
v5.28.0
v5.28.0-RC1
v5.28.0-RC2
v5.28.0-RC3
v5.28.0-RC4
v5.29.0

Database specific

vanir_signatures

[
    {
        "id": "CVE-2018-18311-03a5f7af",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "278762646846467458220749028302630386693",
                "312468557747119978232149888737317887481",
                "161493643322277275457001869997113710198",
                "63943654176538038665800518437507596469",
                "119127681495240114184810842066462406217",
                "296353623599777734216004584012547961258",
                "329292465809237107923465957351581805798",
                "231685815720260020200934945771896543007",
                "178043359333267592176162773375020071429",
                "237183783672896658833163336710383737165",
                "250152108054186789770812128784948443612",
                "213165741231015538985571116828393668584",
                "319370801703202954217563985177783524508",
                "329738588468454201620027238060833819704",
                "314383455144799346142780865009893270760",
                "123801379219583801958491077506912609356",
                "98822304097782848954915188387318587459",
                "71966028249863066924730486223646774984",
                "235924869402854404509950940347127961505",
                "56904741803182023061646506821590483013",
                "34603087930133241378363355428359713696",
                "135544590023977588920973923720912825129",
                "257334656051931252101327244517455703467",
                "205189281332546020698937958583717221794",
                "284566781044160816925880904132687163231",
                "49293671174851459557462202680499054488",
                "282936611618179306955704672491742136335",
                "35188081188623385928179560303844355424",
                "323178167614223974339618985719825179357",
                "227770051973309539615764254246913432760",
                "264590287610024220661636043986184376159",
                "30799101164680659213973560467289847539",
                "273621009362251584277563984863829014714",
                "23732282762801728803277791934274787462",
                "274140217903139139305970336732798880537",
                "113595096881323809552703933403717361115",
                "147607090647580381413665750363608955621",
                "89904576321677848069547443359327286432",
                "211610302220716257581478870691569150871",
                "322799440874947332372700787068003765999",
                "120487017185935785522424645892048162280",
                "1210109423129691442168615330544529791",
                "330360107058339846493926721672137367812",
                "334004709386001461208330486823354622959",
                "250261000308745423778701670392269024960",
                "175842549026026986810812406029634743851",
                "73849908381430057173215485562541545956",
                "251483224424742296371896010847414292954",
                "170300462639422336973054749143305320663",
                "215550845120736407961630486036457954122",
                "274119170000771695150254389561532174435",
                "165250254494429546184372444911738558090",
                "22265498109644917814821019236596096416",
                "230853035943194497847225723510867911094",
                "160096760090148610203933711539747990196",
                "24305426286278845320748928919437622618",
                "10360737222052097615580851996968375620",
                "49141794748794404104407450701925671967",
                "170300462639422336973054749143305320663",
                "215550845120736407961630486036457954122",
                "274119170000771695150254389561532174435",
                "49165777930563725616616829732964403532",
                "178460126831274040021028138488238520464",
                "278994080232964427766074689965611310706",
                "201826042647771855853579827731172743400"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "util.c"
        },
        "source": "https://github.com/perl/perl5/commit/34716e2a6ee2af96078d62b065b7785c001194be",
        "deprecated": false
    }
]