The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "a\x80."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published: 2016-05-25T15:00:00

Updated: 2024-08-06T08:29:22.074Z

Reserved: 2016-04-20T00:00:00

Link: CVE-2015-8853

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-05-25T15:59:01.473

Modified: 2018-05-02T01:29:00.387

Link: CVE-2015-8853

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-01-07T00:00:00Z

Links: CVE-2015-8853 - Bugzilla