[3.10] perl-email-address: DOS vulnerability in perl module Email::Address (CVE-2018-12558)
The parse() method in the Email::Address module through 1.909 for Perl
is vulnerable
to Algorithmic complexity on specially prepared input, leading to Denial
of Service. Prepared
special input that caused this problem contained 30 form-field
characters (“\f”).
References:
https://nvd.nist.gov/vuln/detail/CVE-2018-12558
https://www.openwall.com/lists/oss-security/2018/06/19/3
Patch:
https://github.com/Perl-Email-Project/Email-Address/commit/aeaf0d7f1b0897b54cb246b8ac15d3ef177e5cae
(from redmine: issue id 10431, created on 2019-05-09, closed on 2019-06-13)
- Relations:
- parent #10430 (closed)