CVE-2024-56406

A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, including development versions from 5.33.1 through 5.41.10. When there are non-ASCII bytes in the left-hand-side of the `tr` operator, `S_do_trans_invmap` can overflow the destination pointer `d`.    $ perl -e '$_ = "\x{FF}" x 1000000; tr/\xFF/\x{100}/;'    Segmentation fault (core dumped) It is believed that this vulnerability can enable Denial of Service and possibly Code Execution attacks on platforms that lack sufficient defenses.

Open
MEDIUM (4.5)
  • T

    Tim Bastin detected CVE-2024-56406

  • logo

    System detected CVE-2024-56406

  • logo

    System detected CVE-2024-56406

  • logo

    System detected CVE-2024-56406

  • logo

    System detected CVE-2024-56406

  • T

    Tim Bastin detected CVE-2024-56406

  • logo

    System updated the risk assessment from 0 to 4.5

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0 to 0.9

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0 to 4.5

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0 to 0.9

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0 to 4.5

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0 to 0.9

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0.9 to 4.5

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0.9 to 4.5

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0.9 to 4.5

    System recalculated raw risk assessment

  • logo

    System fixed CVE-2024-56406

  • logo

    System fixed CVE-2024-56406

  • logo

    System fixed CVE-2024-56406

  • logo

    System fixed CVE-2024-56406

  • logo

    System fixed CVE-2024-56406

  • logo

    System fixed CVE-2024-56406

  • logo

    System detected CVE-2024-56406 with a risk of 0.9

  • logo

    System updated the risk assessment from 0.9 to 4.5

    System recalculated raw risk assessment

Add a comment

Mark as False Positive
Last calculated at:

Affected component

debian/perl

Installed version:
5.36.0-7
Fixed in:
no patch available

Management decisions across the organization

Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 2ab7b793efd72421aea8c3a994ac60202bf1b3a5