Advisories Blog | G5 Cyber Security

OpenPKG Security Advisory 2007.23

OpenPKG Security Advisory – Will Drewry and Tavis Ormandy of the Google Security Team have discovered a UTF-8 related heap overflow in the regular expression compiler of the Perl programming language, probably allowing attackers to execute arbitrary code by compiling specially crafted regular expressions. The bug manifests in a possible buffer overflow in the polymorphic “opcode” support code, caused by ASCII regular expressions that really are Unicode regular expressions.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60792/OpenPKG-SA-2007.023.txt

Source: https://packetstormsecurity.com/files/60792/OpenPKG-Security-Advisory-2007.23.html

Exit mobile version