CVE-2020-10878: Integer Overflow
Perl before 5.30.3 has an integer overflow related to mishandling of a "PLregkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
Other sources
Perl. This issue was addressed with improved checks.
Credit
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9927
- CVE-2020-9884
- CVE-2020-9889
- CVE-2020-9888
- CVE-2020-9890
- CVE-2020-9891
- CVE-2020-9928
- CVE-2020-9929
- CVE-2020-9870
- CVE-2020-9866
- CVE-2020-9869
- CVE-2020-9949
- CVE-2020-9934
- CVE-2020-9883
- CVE-2020-9865
- CVE-2020-9900
- CVE-2020-9980
- CVE-2020-9799
- CVE-2020-9913
- CVE-2020-27933
- CVE-2020-11758
- CVE-2020-11759
- CVE-2020-11760
- CVE-2020-11761
- CVE-2020-11762
- CVE-2020-11763
- CVE-2020-11764
- CVE-2020-11765
- CVE-2020-9871
- CVE-2020-9872
- CVE-2020-9874
- CVE-2020-9879
- CVE-2020-9936
- CVE-2020-9937
- CVE-2020-9919
- CVE-2020-9876
- CVE-2020-9873
- CVE-2020-9938
- CVE-2020-9877
- CVE-2020-9875
- CVE-2020-9984
- CVE-2020-9887
- CVE-2020-9908
- CVE-2020-9990
- CVE-2020-9921
- CVE-2019-14899
- CVE-2020-9904
- CVE-2020-9924
- CVE-2020-9892
- CVE-2020-9863
- CVE-2020-9902
- CVE-2020-9905
- CVE-2020-9997
- CVE-2020-9926
- CVE-2020-9994
- CVE-2020-9935
- CVE-2019-19906
- CVE-2020-9920
- CVE-2020-9922
- CVE-2020-9885
- CVE-2020-9878
- CVE-2020-9880
- CVE-2020-9881
- CVE-2020-9882
- CVE-2020-9940
- CVE-2020-9985
- CVE-2020-12243
- CVE-2020-10878
- CVE-2020-12723
- CVE-2014-9512
- CVE-2020-9930
- CVE-2020-9939
- CVE-2020-9864
- CVE-2020-9868
- CVE-2020-9854
- CVE-2020-9901
- CVE-2019-20807
- CVE-2020-9898
- CVE-2020-9918
- CVE-2020-9899
- CVE-2020-9906
Frequently Asked Questions
What is CVE-2020-10878?
CVE-2020-10878 is a vulnerability in Perl that has been addressed with improved checks.
Which software versions are affected by CVE-2020-10878?
macOS Catalina version 10.15.6, Apple Mojave, and Apple High Sierra are affected by CVE-2020-10878.
How can I fix CVE-2020-10878?
Update to macOS Catalina version 10.15.6 or apply the necessary patches provided by Apple to fix CVE-2020-10878.
Where can I find more information about CVE-2020-10878?
You can find more information about CVE-2020-10878 on the official Apple support website at: https://support.apple.com/en-us/HT211289
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2020-10878?
The CWE ID associated with CVE-2020-10878 is CWE-190.