CVE-2018-6913: Buffer Overflow
Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.
Other sources
Perl. Multiple issues in Perl were addressed with improved memory handling.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOS High Sierrato a version that resolves this vulnerability.Fixed in 10.13.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.5.117.1.3 - Upgrade
Upgrade
debian/perlto a version that resolves this vulnerability.Fixed in 5.32.1-4+deb11u3Fixed in 5.32.1-4+deb11u5Fixed in 5.36.0-7+deb12u3Fixed in 5.36.0-7+deb12u2Fixed in 5.40.1-6Fixed in 5.40.1-8 - Upgrade
Upgrade
Perlto a version that resolves this vulnerability.Fixed in 5.26.2
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4470
- CVE-2018-4289
- CVE-2018-4268
- CVE-2018-4285
- CVE-2018-5383
- CVE-2018-4293
- CVE-2018-4269
- CVE-2018-4276
- CVE-2018-4178
- CVE-2018-4456
- CVE-2018-4283
- CVE-2018-3665
- CVE-2018-4259
- CVE-2018-4286
- CVE-2018-4287
- CVE-2018-4288
- CVE-2018-4291
- CVE-2018-4280
- CVE-2018-4248
- CVE-2018-4277
- CVE-2018-6797
- CVE-2018-6913
- CVE-2017-0898
- CVE-2017-10784
- CVE-2017-14033
- CVE-2017-14064
- CVE-2017-17405
- CVE-2017-17742
- CVE-2018-6914
- CVE-2018-8777
- CVE-2018-8778
- CVE-2018-8779
- CVE-2018-8780
- CVE-2018-4274
Frequently Asked Questions
What is CVE-2018-6913?
CVE-2018-6913 is a vulnerability in Perl that allows attackers to execute arbitrary code through a heap-based buffer overflow in the pack function.
How severe is CVE-2018-6913?
CVE-2018-6913 is classified as critical with a severity rating of 9.8.
Which software versions are affected by CVE-2018-6913?
Perl versions before 5.26.2 are affected by CVE-2018-6913.
How can I fix CVE-2018-6913?
To fix CVE-2018-6913, update Perl to version 5.26.2 or later.
Where can I find more information about CVE-2018-6913?
You can find more information about CVE-2018-6913 on the MITRE CVE database and the Ubuntu security notices.