CVE-2013-7422

high
Published 2015-08-16 · Modified 2026-05-06
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-7422

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://support.apple.com/kb/HT205031

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html

OS impact

OSVersionStatusFixed in
macos macosaffected
debian debianbookwormfixed5.20.0-1
debian debianbullseyefixed5.20.0-1
debian debianforkyfixed5.20.0-1
debian debiansidfixed5.20.0-1
debian debiantrixiefixed5.20.0-1

Application impact

VendorProductVersionsFixed
perlperl5.18.4

References

CWEs

CWE-189

Verify integrity in audit chain (admin only). AS-IS.