CVE Vulnerabilities

CVE-2014-0477

Published: Jul 03, 2014 | Modified: Nov 04, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The parse function in Email::Address module before 1.905 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via an empty quoted string in an RFC 2822 address.

Affected Software

Name Vendor Start Version End Version
Email::address Email::address_module_project * 1.904 (including)
Email::address Email::address_module_project 1.1 (including) 1.1 (including)
Email::address Email::address_module_project 1.2 (including) 1.2 (including)
Email::address Email::address_module_project 1.3 (including) 1.3 (including)
Email::address Email::address_module_project 1.5 (including) 1.5 (including)
Email::address Email::address_module_project 1.6 (including) 1.6 (including)
Email::address Email::address_module_project 1.7 (including) 1.7 (including)
Email::address Email::address_module_project 1.80 (including) 1.80 (including)
Email::address Email::address_module_project 1.85 (including) 1.85 (including)
Email::address Email::address_module_project 1.86 (including) 1.86 (including)
Email::address Email::address_module_project 1.870 (including) 1.870 (including)
Email::address Email::address_module_project 1.871 (including) 1.871 (including)
Email::address Email::address_module_project 1.880 (including) 1.880 (including)
Email::address Email::address_module_project 1.881 (including) 1.881 (including)
Email::address Email::address_module_project 1.882 (including) 1.882 (including)
Email::address Email::address_module_project 1.883 (including) 1.883 (including)
Email::address Email::address_module_project 1.884 (including) 1.884 (including)
Email::address Email::address_module_project 1.885 (including) 1.885 (including)
Email::address Email::address_module_project 1.886 (including) 1.886 (including)
Email::address Email::address_module_project 1.887 (including) 1.887 (including)
Email::address Email::address_module_project 1.888 (including) 1.888 (including)
Email::address Email::address_module_project 1.889 (including) 1.889 (including)
Email::address Email::address_module_project 1.890 (including) 1.890 (including)
Email::address Email::address_module_project 1.891 (including) 1.891 (including)
Email::address Email::address_module_project 1.892 (including) 1.892 (including)
Email::address Email::address_module_project 1.893 (including) 1.893 (including)
Email::address Email::address_module_project 1.894 (including) 1.894 (including)
Email::address Email::address_module_project 1.895 (including) 1.895 (including)
Email::address Email::address_module_project 1.896 (including) 1.896 (including)
Email::address Email::address_module_project 1.897 (including) 1.897 (including)
Email::address Email::address_module_project 1.898 (including) 1.898 (including)
Email::address Email::address_module_project 1.899 (including) 1.899 (including)
Email::address Email::address_module_project 1.900 (including) 1.900 (including)
Email::address Email::address_module_project 1.901 (including) 1.901 (including)
Email::address Email::address_module_project 1.902 (including) 1.902 (including)
Email::address Email::address_module_project 1.903 (including) 1.903 (including)
Fedora Fedoraproject * *
Libemail-address-perl Ubuntu lucid *
Libemail-address-perl Ubuntu precise *
Libemail-address-perl Ubuntu saucy *
Libemail-address-perl Ubuntu trusty *
Libemail-address-perl Ubuntu upstream *

References