Vulnerability Report

CVE-2007-5116

RCE

Title: Openpkg RCE

RCE

Proof Of Concept

No public PoC currently indexed for CVE-2007-5116.

CWE Category CWE-119
Published Date Nov 07, 2007
Modified Date Apr 09, 2025
Exploit Status Not Found
Score 7.5 CVSS v2.0
Exploit Probability (EPSS)
8.80%

Vulnerability Summary

CVE-2007-5116: Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.

Impacted Vendors

Reference Links

ftp://aix.software.ibm.com/aix/efixes/security/README http://docs.info.apple.com/article.html?artnum=307179 http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html http://lists.vmware.com/pipermail/security-announce/2008/000002.html http://marc.info/?l=bugtraq&m=120352263023774&w=2 http://secunia.com/advisories/27479 http://secunia.com/advisories/27515 http://secunia.com/advisories/27531 http://secunia.com/advisories/27546 http://secunia.com/advisories/27548 http://secunia.com/advisories/27570 http://secunia.com/advisories/27613 http://secunia.com/advisories/27756 http://secunia.com/advisories/27936 http://secunia.com/advisories/28167 http://secunia.com/advisories/28368 http://secunia.com/advisories/28387 http://secunia.com/advisories/28993 http://secunia.com/advisories/29074 http://secunia.com/advisories/31208 http://securitytracker.com/id?1018899 http://sunsolve.sun.com/search/document.do?assetkey=1-26-31524-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-231524-1 http://sunsolve.sun.com/search/document.do?assetkey=1-77-1018985.1-1 http://support.avaya.com/elmodocs2/security/ASA-2008-014.htm http://www-1.ibm.com/support/docview.wss?uid=isg1IZ10220 http://www-1.ibm.com/support/docview.wss?uid=isg1IZ10244 http://www.debian.org/security/2007/dsa-1400 http://www.gentoo.org/security/en/glsa/glsa-200711-28.xml http://www.ipcop.org/index.php?name=News&file=article&sid=41 http://www.mandriva.com/security/advisories?name=MDKSA-2007:207 http://www.novell.com/linux/security/advisories/2007_24_sr.html http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.023.html http://www.redhat.com/support/errata/RHSA-2007-0966.html http://www.redhat.com/support/errata/RHSA-2007-1011.html http://www.securityfocus.com/archive/1/483563/100/0/threaded http://www.securityfocus.com/archive/1/483584/100/0/threaded http://www.securityfocus.com/archive/1/485936/100/0/threaded http://www.securityfocus.com/archive/1/486859/100/0/threaded http://www.securityfocus.com/bid/26350 http://www.ubuntu.com/usn/usn-552-1 http://www.us-cert.gov/cas/techalerts/TA07-352A.html http://www.vmware.com/security/advisories/VMSA-2008-0001.html http://www.vupen.com/english/advisories/2007/3724 http://www.vupen.com/english/advisories/2007/4238 http://www.vupen.com/english/advisories/2007/4255 http://www.vupen.com/english/advisories/2008/0064 http://www.vupen.com/english/advisories/2008/0641 https://bugzilla.redhat.com/show_bug.cgi?id=323571 https://bugzilla.redhat.com/show_bug.cgi?id=378131 https://exchange.xforce.ibmcloud.com/vulnerabilities/38270 https://issues.rpath.com/browse/RPL-1813 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10669 ftp://aix.software.ibm.com/aix/efixes/security/README http://docs.info.apple.com/article.html?artnum=307179 http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html http://lists.vmware.com/pipermail/security-announce/2008/000002.html http://marc.info/?l=bugtraq&m=120352263023774&w=2 http://secunia.com/advisories/27479 http://secunia.com/advisories/27515 http://secunia.com/advisories/27531 http://secunia.com/advisories/27546 http://secunia.com/advisories/27548 http://secunia.com/advisories/27570 http://secunia.com/advisories/27613 http://secunia.com/advisories/27756 http://secunia.com/advisories/27936 http://secunia.com/advisories/28167 http://secunia.com/advisories/28368 http://secunia.com/advisories/28387 http://secunia.com/advisories/28993 http://secunia.com/advisories/29074 http://secunia.com/advisories/31208 http://securitytracker.com/id?1018899 http://sunsolve.sun.com/search/document.do?assetkey=1-26-31524-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-231524-1 http://sunsolve.sun.com/search/document.do?assetkey=1-77-1018985.1-1 http://support.avaya.com/elmodocs2/security/ASA-2008-014.htm http://www-1.ibm.com/support/docview.wss?uid=isg1IZ10220 http://www-1.ibm.com/support/docview.wss?uid=isg1IZ10244 http://www.debian.org/security/2007/dsa-1400 http://www.gentoo.org/security/en/glsa/glsa-200711-28.xml http://www.ipcop.org/index.php?name=News&file=article&sid=41 http://www.mandriva.com/security/advisories?name=MDKSA-2007:207 http://www.novell.com/linux/security/advisories/2007_24_sr.html http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.023.html http://www.redhat.com/support/errata/RHSA-2007-0966.html http://www.redhat.com/support/errata/RHSA-2007-1011.html http://www.securityfocus.com/archive/1/483563/100/0/threaded http://www.securityfocus.com/archive/1/483584/100/0/threaded http://www.securityfocus.com/archive/1/485936/100/0/threaded http://www.securityfocus.com/archive/1/486859/100/0/threaded http://www.securityfocus.com/bid/26350 http://www.ubuntu.com/usn/usn-552-1 http://www.us-cert.gov/cas/techalerts/TA07-352A.html http://www.vmware.com/security/advisories/VMSA-2008-0001.html http://www.vupen.com/english/advisories/2007/3724 http://www.vupen.com/english/advisories/2007/4238 http://www.vupen.com/english/advisories/2007/4255 http://www.vupen.com/english/advisories/2008/0064 http://www.vupen.com/english/advisories/2008/0641 https://bugzilla.redhat.com/show_bug.cgi?id=323571 https://bugzilla.redhat.com/show_bug.cgi?id=378131 https://exchange.xforce.ibmcloud.com/vulnerabilities/38270 https://issues.rpath.com/browse/RPL-1813 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10669
CVSS v2.0
Source Entity [email protected]
Severity HIGH
7.5
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:P/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2007-5116 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected Stack

No specific products linked.