perl-email-address: DOS vulnerability in perl module Email::Address (CVE-2018-12558)
The parse() method in the Email::Address module through 1.909 for Perl
is vulnerable
to Algorithmic complexity on specially prepared input, leading to Denial
of Service. Prepared
special input that caused this problem contained 30 form-field
characters (“\f”).
References:
https://nvd.nist.gov/vuln/detail/CVE-2018-12558
https://www.openwall.com/lists/oss-security/2018/06/19/3
Patch:
https://github.com/Perl-Email-Project/Email-Address/commit/aeaf0d7f1b0897b54cb246b8ac15d3ef177e5cae
(from redmine: issue id 10430, created on 2019-05-09)
- Relations:
- child #10431 (closed)
- child #10432 (closed)
- child #10433 (closed)
- child #10435 (closed)