CVE-2020-10543: Fedoraproject Fedora

High severity, CVSS 8.2. EPSS: 11.3% chance of exploitation in the next 30 days.

Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.

Affected products

  • Fedoraproject Fedora: version 31 only
  • Opensuse Leap: version 15.1 only
  • Oracle Communications Billing And Revenue Management: version 12.0.0.2.0 only; version 12.0.0.3.0 only
  • Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.5.0
  • Oracle Communications Eagle Application Processor: from 16.1.0, up to and including 16.4.0
  • Oracle Communications Eagle Lnp Application Processor: version 10.1 only; version 10.2 only; version 46.7 only; version 46.8 only; version 46.9 only
  • Oracle Communications Lsms: from 13.1, up to and including 13.4
  • Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
  • Oracle Communications Performance Intelligence Center: from 10.3.0.0.0, up to and including 10.3.0.2.1; from 10.4.0.1.0, up to and including 10.4.0.3.1
  • Oracle Communications Pricing Design Center: version 12.0.0.3.0 only
  • Oracle Configuration Manager: version 12.1.2.0.8 only
  • Oracle Enterprise Manager Base Platform: version 13.4.0.0 only
  • Oracle SD-WAN Edge: version 8.2 only; version 9.0 only; version 9.1 only
  • Oracle Tekelec Platform Distribution: from 7.4.0, up to and including 7.7.1
  • Perl Perl: before 5.30.3 (fixed in 5.30.3)

Published 2020-06-05. Last modified 2026-06-17.