CVE-2012-5195

high
Published 2012-12-18 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 allows context-dependent attackers to cause a denial of service (memory consumption and crash) or possibly execute arbitrary code via the 'x' string repeat operator.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-5195

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/51457

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://perl5.git.perl.org/perl.git/commit/2709980d5a193ce6f3a16f0d19879a6560dcde44

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed5.14.2-14
debian debianbullseyefixed5.14.2-14
debian debianforkyfixed5.14.2-14
debian debiansidfixed5.14.2-14
debian debiantrixiefixed5.14.2-14

Application impact

VendorProductVersionsFixed
perlperl5.12.0
perlperl5.12.1
perlperl5.12.2
perlperl5.12.3
perlperl5.12.4
perlperl5.14.0
perlperl5.14.1
perlperl5.14.2

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.