Back to Database
Status published
Critical
CVE-2018-18312
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer...
Vulnerability Description
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-18312
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.debian.org/security/2018/dsa-4347
- http://www.securityfocus.com/bid/106179
- http://www.securitytracker.com/id/1042181
- https://access.redhat.com/errata/RHSA-2019:0010
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWQGEB543QN7SSBRKYJM6PSOC3RLYGSM/
- https://access.redhat.com/errata/RHSA-2019:0001
- https://usn.ubuntu.com/3834-1/
- https://security.gentoo.org/glsa/201909-01
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://security.netapp.com/advisory/ntap-20190221-0003/
- https://metacpan.org/changes/release/SHAY/perl-5.26.3
- https://metacpan.org/changes/release/SHAY/perl-5.28.1
- https://bugzilla.redhat.com/show_bug.cgi?id=1646734
- https://rt.perl.org/Public/Bug/Display.html?id=133423
More from perl
View All →CVE-2025-40909
Perl threads have a working directory race condition where file operations may target unintended paths
Unknown
0
CVE-2025-1828
Perl's Crypt::Random module after 1.05 and before 1.56 may use rand() function for cryptographic functions
Unknown
0
CVE-2024-56406
Perl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytes
Unknown
0
CVE-2022-48522
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based...
Critical
9.8
CVE-2020-16156
CPAN 2.28 allows Signature Verification Bypass....
High
7.8
Affected Vendor
perl
View all reports →Affected Software
perl, ubuntu linux, debian linux, enterprise linux, e-series santricity os controller, snap creator framework, snapcenter, snapdrive
Vulnerable Versions:
0, 5.28.0, 14.04, 16.04, 18.04, 18.10, 9.0, 6.0, 7.0, 7.4, 7.5, 7.6, 11.0
Timeline
Official Publish:
December 5th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.