Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mac_os_x | Apple | * | 10.10.4 (including) |
Perl | Ubuntu | lucid | * |
Perl | Ubuntu | precise | * |
Perl | Ubuntu | trusty | * |
Perl | Ubuntu | upstream | * |