Upstream information

CVE-2011-2939 at MITRE

Description

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 5.10
Vector AV:N/AC:H/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 728662 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 11.3
openSUSE 11.4
  • icedtea-web >= 1.1.4-0.2.1
  • icedtea-web-javadoc >= 1.1.4-0.2.1
openSUSE 11.3
  • perl-base-debuginfo >= 5.12.1-2.7.1
  • perl-base-debuginfo-32bit >= 5.12.1-2.7.1
  • perl-debuginfo >= 5.12.1-2.7.1
  • perl-debuginfo-32bit >= 5.12.1-2.7.1
  • perl-debugsource >= 5.12.1-2.7.1
openSUSE 11.3
  • perl >= 5.12.1-2.7.1
  • perl-32bit >= 5.12.1-2.7.1
  • perl-base >= 5.12.1-2.7.1
  • perl-base-32bit >= 5.12.1-2.7.1
  • perl-doc >= 5.12.1-2.7.1
openSUSE 11.4
  • perl >= 5.12.3-11.18.1
  • perl-32bit >= 5.12.3-11.18.1
  • perl-base >= 5.12.3-11.18.1
  • perl-base-32bit >= 5.12.3-11.18.1
  • perl-doc >= 5.12.3-11.18.1
openSUSE 11.4
  • icedtea-web >= 1.1.4-0.2.1
  • icedtea-web-javadoc >= 1.1.4-0.2.1
  • java-1_6_0-openjdk >= 1.6.0.0_b22.1.10.2-4.3.1
  • java-1_6_0-openjdk-debuginfo >= 1.6.0.0_b22.1.10.2-4.3.1
  • java-1_6_0-openjdk-debugsource >= 1.6.0.0_b22.1.10.2-4.3.1
  • java-1_6_0-openjdk-demo >= 1.6.0.0_b22.1.10.2-4.3.1
  • java-1_6_0-openjdk-devel >= 1.6.0.0_b22.1.10.2-4.3.1
  • java-1_6_0-openjdk-devel-debuginfo >= 1.6.0.0_b22.1.10.2-4.3.1
  • java-1_6_0-openjdk-javadoc >= 1.6.0.0_b22.1.10.2-4.3.1
  • java-1_6_0-openjdk-src >= 1.6.0.0_b22.1.10.2-4.3.1
  • perl >= 5.12.3-11.18.1
  • perl-32bit >= 5.12.3-11.18.1
  • perl-base >= 5.12.3-11.18.1
  • perl-base-32bit >= 5.12.3-11.18.1
  • perl-base-debuginfo >= 5.12.3-11.18.1
  • perl-base-debuginfo-32bit >= 5.12.3-11.18.1
  • perl-debuginfo >= 5.12.3-11.18.1
  • perl-debuginfo-32bit >= 5.12.3-11.18.1
  • perl-debugsource >= 5.12.3-11.18.1
  • perl-doc >= 5.12.3-11.18.1
Patchnames:
icedtea-web
perl