Skip to main content

Numeric Errors

CVE-2013-7422

Severity High
Score 7.5/10

Summary

Integer underflow in "regcomp.c" in Perl through 5.18.1 and 5.19.0 through 5.19.4, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a Denial of Service (application crash) via a long digit string associated with an invalid backreference within a regular expression.

  • LOW
  • NETWORK
  • NONE
  • PARTIAL
  • PARTIAL
  • PARTIAL

CWE-189 - Numeric Errors

Weaknesses in this category are related to improper calculation or conversion of numbers.

Advisory Timeline

  • Published