CVE-2018-18313: Critical severity Apple macOS Mojave vulnerability
A flaw was found in Perl versions 5.22 through 5.26. Heap-buffer-overflow read in regcomp.c
Upstream Patch: https://github.com/Perl/perl5/commit/43b2f4ef399e2fd7240b4eeb0658686ad95f8e62
Other sources
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
— Launchpad
Perl. Multiple issues in Perl were addressed in this update.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-6203
- CVE-2019-8531
- CVE-2019-8538
- CVE-2019-8534
- CVE-2019-8555
- CVE-2019-6239
- CVE-2019-8516
- CVE-2019-8552
- CVE-2019-8511
- CVE-2019-8542
- CVE-2019-8522
- CVE-2019-8550
- CVE-2019-8777
- CVE-2019-8565
- CVE-2019-8521
- CVE-2019-8906
- CVE-2019-8519
- CVE-2019-8533
- CVE-2019-8545
- CVE-2019-8504
- CVE-2019-8529
- CVE-2018-4448
- CVE-2019-5608
- CVE-2019-8527
- CVE-2019-8528
- CVE-2019-8508
- CVE-2019-8514
- CVE-2019-8540
- CVE-2019-7293
- CVE-2019-6207
- CVE-2019-8510
- CVE-2019-8547
- CVE-2019-8525
- CVE-2018-4433
- CVE-2019-8642
- CVE-2019-8645
- CVE-2019-8546
- CVE-2019-8579
- CVE-2019-8537
- CVE-2019-8561
- CVE-2018-12015
- CVE-2018-18311
- CVE-2018-18313
- CVE-2019-8549
- CVE-2019-8507
- CVE-2019-8618
- CVE-2019-8526
- CVE-2019-8520
- CVE-2019-8502
- CVE-2019-8513
- CVE-2019-8569
- CVE-2019-8517
- CVE-2019-8564
- CVE-2019-8612
- CVE-2019-8567
- CVE-2019-6238
- CVE-2019-8530
Frequently Asked Questions
What is CVE-2018-18313?
CVE-2018-18313 is a vulnerability in Perl that allows for a buffer over-read which can lead to disclosure of sensitive information.
How severe is CVE-2018-18313?
CVE-2018-18313 has a severity score of 9.1, which is considered critical.
Which software versions are affected by CVE-2018-18313?
Perl versions before 5.26.3 are affected by CVE-2018-18313.
What is the remedy for CVE-2018-18313?
To fix CVE-2018-18313, upgrade Perl to version 5.26.3 or later.
Where can I find more information about CVE-2018-18313?
You can find more information about CVE-2018-18313 at the following references: [Link 1](http://seclists.org/fulldisclosure/2019/Mar/49), [Link 2](http://www.securitytracker.com/id/1042181), [Link 3](https://access.redhat.com/errata/RHSA-2019:0001).