Security Advisories (1)
CVE-2018-12558 (2018-06-19)

The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").

Changes for version 1.904 - 2014-06-14 (TRIAL RELEASE)

  • avoid being fooled by an addr-like string in the phrase
  • avoid a slowdown by avoiding backtracking into the phrase

Modules

RFC 2822 Address Parsing and Creation