CVE-2010-4777
Estado: ModificadaMedia (4.3)—💥 Exploit
The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debugging enabled, allows context-dependent attackers to cause a denial of service (assertion failure and application exit) via crafted input that is not properly handled when using certain regular expressions, as demonstrated by causing SpamAssassin and OCSInventory to crash.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.02%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Perl 5.x - 'Perl_reg_numbered_buff_fetch()' Remote Denial of Service (23/3/2011)
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628836
- http://forums.ocsinventory-ng.org/viewtopic.php?id=7215
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
- http://lists.opensuse.org/opensuse-updates/2011-05/msg00025.html
- https://bugzilla.redhat.com/show_bug.cgi?id=694166
- https://listi.jpberlin.de/pipermail/postfixbuch-users/2011-February/055885.html
- https://rt.perl.org/Public/Bug/Display.html?id=76538
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628836
- http://forums.ocsinventory-ng.org/viewtopic.php?id=7215
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
- http://lists.opensuse.org/opensuse-updates/2011-05/msg00025.html
- https://bugzilla.redhat.com/show_bug.cgi?id=694166
- https://listi.jpberlin.de/pipermail/postfixbuch-users/2011-February/055885.html
- https://rt.perl.org/Public/Bug/Display.html?id=76538
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-4777",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-02-10T18:15:08.967",
"references": [
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628836",
"source": "cve@mitre.org"
},
{
"url": "http://forums.ocsinventory-ng.org/viewtopic.php?id=7215",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2011-05/msg00025.html",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=694166",
"source": "cve@mitre.org"
},
{
"url": "https://listi.jpberlin.de/pipermail/postfixbuch-users/2011-February/055885.html",
"source": "cve@mitre.org"
},
{
"url": "https://rt.perl.org/Public/Bug/Display.html?id=76538",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628836",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://forums.ocsinventory-ng.org/viewtopic.php?id=7215",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2011-05/msg00025.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=694166",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://listi.jpberlin.de/pipermail/postfixbuch-users/2011-February/055885.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://rt.perl.org/Public/Bug/Display.html?id=76538",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debugging enabled, allows context-dependent attackers to cause a denial of service (assertion failure and application exit) via crafted input that is not properly handled when using certain regular expressions, as demonstrated by causing SpamAssassin and OCSInventory to crash."
},
{
"lang": "es",
"value": "La función Perl_reg_numbered_buff_fetch en Perl 5.10.0, 5.12.0, 5.14.0 y otras versiones, cuando funciona con debugging activado, permite a atacantes dependientes de contexto causar una denegación de servicio (fallo de aserción y cierre de la aplicación) a través de una entrada manipulada que no es manejada adecuadamente cuando hace uso de ciertas expresiones regulares, como se ha demostrado causando la caída de SpamAssassin y OCSInventory."
}
],
"lastModified": "2026-06-16T23:25:31.617",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:perl:perl:5.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "777EC860-FB16-4B15-A8BE-3EAE9FD8A99D"
},
{
"criteria": "cpe:2.3:a:perl:perl:5.12.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BC3F8EA-BE60-4EAB-A9B9-DB1368B5430C"
},
{
"criteria": "cpe:2.3:a:perl:perl:5.14.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A968B30-8456-49C2-A9B0-6CF55CB3C7B4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}