Impact
Perl versions through 5.43.10 contain an integer overflow in the internal function S_measure_struct, which accumulates item sizes for pack and unpack templates without performing an overflow check. When a template specifies an exceedingly large repeat count, the signed length checks incorrectly succeed, allowing the buffer pointer to advance beyond its intended bounds and read arbitrary heap memory. The data read in this manner is then returned to the caller, enabling disclosure of confidential information.
Affected Systems
Perl releases up to and including version 5.43.10 are affected. The fix was incorporated into the 5.43.11 development release, so systems running 5.43.10 or earlier should upgrade to 5.43.11 or a later version.
Risk and Exploitability
The CVSS score of 8.4 and an EPSS score of < 1% indicate a high potential impact but a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can supply a malicious pack or unpack template derived from untrusted input—such as user‑controlled scripts or web applications that process external data—thereby triggering the out‑of‑bounds read. Successful exploitation would be local to the environment that executes the Perl code, but the compromised data can potentially be exfiltrated if the process has network access or is part of a larger compromised system.
OpenCVE Enrichment