CVE-2020-12723: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 6% chance of exploitation in the next 30 days.

regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.

Affected products

  • Fedoraproject Fedora: version 31 only
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Snap Creator Framework: affected versions not specified
  • Opensuse Leap: version 15.1 only
  • Oracle Communications Billing And Revenue Management: version 12.0.0.2.0 only; version 12.0.0.3.0 only
  • Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.5.0
  • Oracle Communications Eagle Application Processor: from 16.1.0, up to and including 16.4.0
  • Oracle Communications Eagle Lnp Application Processor: version 10.1 only; version 10.2 only
  • Oracle Communications Lsms: from 13.1, up to and including 13.4
  • Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
  • Oracle Communications Performance Intelligence Center: from 10.3.0.0.0, up to and including 10.3.0.2.1; from 10.4.0.1.0, up to and including 10.4.0.3.1
  • Oracle Configuration Manager: version 12.1.2.0.8 only
  • Oracle Enterprise Manager Base Platform: version 13.4.0.0 only
  • Oracle SD-WAN Edge: version 8.2 only; version 9.0 only; version 9.1 only
  • Oracle Tekelec Platform Distribution: from 7.4.0, up to and including 7.7.1
  • Perl Perl: before 5.30.3 (fixed in 5.30.3)

Published 2020-06-05. Last modified 2026-06-17.