CVE-2010-4777
The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debugging enabled, allows context-dependent...
- Published
- Feb 10, 2014
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- Mar 23, 2011
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:PLow · next 30 days
- Percentile
- 93.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debugging enabled, allows context-dependent attackers to cause a denial of service (assertion failure and application exit) via crafted input that is not properly handled when using certain regular expressions, as demonstrated by causing SpamAssassin and OCSInventory to crash.
Sources
1Vladimir Perepelitsa · multiple · Mar 23, 2011
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.