UBUNTU-CVE-2023-47038

Source
https://ubuntu.com/security/CVE-2023-47038
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-47038.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2023-47038
Related
Published
2023-11-25T17:00:00Z
Modified
2024-10-15T14:11:50Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.

References

Affected packages

Ubuntu:Pro:18.04:LTS / perl6

Package

Name
perl6
Purl
pkg:deb/ubuntu/perl6?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.c-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / perl

Package

Name
perl
Purl
pkg:deb/ubuntu/perl?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.30.0-9ubuntu0.5

Affected versions

5.*

5.28.1-6build1
5.30.0-7
5.30.0-9
5.30.0-9build1
5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.4

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "5.30.0-9ubuntu0.5",
            "binary_name": "libperl-dev"
        },
        {
            "binary_version": "5.30.0-9ubuntu0.5",
            "binary_name": "libperl5.30"
        },
        {
            "binary_version": "5.30.0-9ubuntu0.5",
            "binary_name": "perl"
        },
        {
            "binary_version": "5.30.0-9ubuntu0.5",
            "binary_name": "perl-base"
        },
        {
            "binary_version": "5.30.0-9ubuntu0.5",
            "binary_name": "perl-debug"
        },
        {
            "binary_version": "5.30.0-9ubuntu0.5",
            "binary_name": "perl-doc"
        },
        {
            "binary_version": "5.30.0-9ubuntu0.5",
            "binary_name": "perl-modules-5.30"
        }
    ]
}

Ubuntu:20.04:LTS / perl6

Package

Name
perl6
Purl
pkg:deb/ubuntu/perl6?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.d-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / perl

Package

Name
perl
Purl
pkg:deb/ubuntu/perl?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.34.0-3ubuntu1.3

Affected versions

5.*

5.32.1-3ubuntu3
5.34.0-3ubuntu1
5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "5.34.0-3ubuntu1.3",
            "binary_name": "libperl-dev"
        },
        {
            "binary_version": "5.34.0-3ubuntu1.3",
            "binary_name": "libperl5.34"
        },
        {
            "binary_version": "5.34.0-3ubuntu1.3",
            "binary_name": "perl"
        },
        {
            "binary_version": "5.34.0-3ubuntu1.3",
            "binary_name": "perl-base"
        },
        {
            "binary_version": "5.34.0-3ubuntu1.3",
            "binary_name": "perl-debug"
        },
        {
            "binary_version": "5.34.0-3ubuntu1.3",
            "binary_name": "perl-doc"
        },
        {
            "binary_version": "5.34.0-3ubuntu1.3",
            "binary_name": "perl-modules-5.34"
        }
    ]
}

Ubuntu:24.10 / raku

Package

Name
raku
Purl
pkg:deb/ubuntu/raku?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.d.7

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / perl

Package

Name
perl
Purl
pkg:deb/ubuntu/perl?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.36.0-10ubuntu1

Affected versions

5.*

5.36.0-9ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "5.36.0-10ubuntu1",
            "binary_name": "libperl-dev"
        },
        {
            "binary_version": "5.36.0-10ubuntu1",
            "binary_name": "libperl5.36"
        },
        {
            "binary_version": "5.36.0-10ubuntu1",
            "binary_name": "perl"
        },
        {
            "binary_version": "5.36.0-10ubuntu1",
            "binary_name": "perl-base"
        },
        {
            "binary_version": "5.36.0-10ubuntu1",
            "binary_name": "perl-debug"
        },
        {
            "binary_version": "5.36.0-10ubuntu1",
            "binary_name": "perl-doc"
        },
        {
            "binary_version": "5.36.0-10ubuntu1",
            "binary_name": "perl-modules-5.36"
        }
    ]
}

Ubuntu:24.04:LTS / raku

Package

Name
raku
Purl
pkg:deb/ubuntu/raku?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.d.7

Ecosystem specific

{
    "ubuntu_priority": "medium"
}