mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
26 lines
1.6 KiB
Markdown
26 lines
1.6 KiB
Markdown
### [CVE-2024-56406](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-56406)
|
||

|
||

|
||

|
||

|
||

|
||

|
||
|
||
### Description
|
||
|
||
A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, including development versions from 5.33.1 through 5.41.10.When there are non-ASCII bytes in the left-hand-side of the `tr` operator, `S_do_trans_invmap` can overflow the destination pointer `d`. $ perl -e '$_ = "\x{FF}" x 1000000; tr/\xFF/\x{100}/;' Segmentation fault (core dumped)It is believed that this vulnerability can enable Denial of Service and possibly Code Execution attacks on platforms that lack sufficient defenses.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
No PoCs from references.
|
||
|
||
#### Github
|
||
- https://github.com/11notes/docker-github-runner
|
||
- https://github.com/ARPSyndicate/cve-scores
|
||
- https://github.com/adegoodyer/kubernetes-admin-toolkit
|
||
- https://github.com/andreazorzetto/test-flask
|
||
- https://github.com/httpoz/wachturm
|
||
- https://github.com/runwhen-contrib/helm-charts
|
||
|