Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
{ "vanir_signatures": [ { "id": "CVE-2020-10543-501f156b", "digest": { "length": 39449.0, "function_hash": "188038057978112623465644672548025025841" }, "signature_version": "v1", "target": { "function": "S_study_chunk", "file": "regcomp.c" }, "source": "https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed", "deprecated": false, "signature_type": "Function" }, { "id": "CVE-2020-10543-b76d07fc", "digest": { "line_hashes": [ "326227367672465616021991049804010148793", "15134703551330238417109193759520969772", "336883495148109590279206088498136563982" ], "threshold": 0.9 }, "signature_version": "v1", "target": { "file": "regcomp.c" }, "source": "https://github.com/perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed", "deprecated": false, "signature_type": "Line" } ] }