Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-5116

23
FAUCET Score

CVE-2007-5116 describes a buffer overflow vulnerability in the Perl 5.8 Regular Expression Engine, specifically within its polymorphic opcode support. This flaw allows attackers to execute arbitrary code by manipulating regular expressions to switch between byte and Unicode characters, affecting various distributions including Debian, Red Hat, and Mandrakesoft. With a CVSS score of 7.5, it is considered highly severe due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting it is not currently a high-profile threat.

Impacted Technologies

VendorProductVersion(s)CPE
5.8.0CPE matchmatch criteria
cpe:2.3:a:larry_wall:perl:5.8.0:*:*:*:*:*:*:*
5.8.1CPE matchmatch criteria
cpe:2.3:a:larry_wall:perl:5.8.1:*:*:*:*:*:*:*
5.8.3CPE matchmatch criteria
cpe:2.3:a:larry_wall:perl:5.8.3:*:*:*:*:*:*:*
5.8.4CPE matchmatch criteria
cpe:2.3:a:larry_wall:perl:5.8.4:*:*:*:*:*:*:*
5.8.4.1CPE matchmatch criteria
cpe:2.3:a:larry_wall:perl:5.8.4.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.83%
Probability of exploitation in next 30 days
EPSS Percentile
91.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0483 is in the 84th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: ant-0:1.6.5-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: avalon-logkit-0:1.2-2jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: axis-0:1.2.1-1jpp_3rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-jaf-0:1.0-2jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-mail-0:1.1.1-2jpp_8rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: geronimo-specs-0:1.0-0.M4.1jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: jakarta-commons-modeler-0:2.0-3jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: log4j-0:1.2.12-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: mx4j-1:3.0.1-1jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: pcsc-lite-0:1.3.3-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ca-0:7.3.0-20.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-java-tools-0:7.3.0-10.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-kra-0:7.3.0-14.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-manage-0:7.3.0-19.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-native-tools-0:7.3.0-6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ocsp-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-tks-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: tomcat5-0:5.5.23-0jpp_4rh.16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xerces-j2-0:2.7.1-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xml-commons-0:1.3.02-2jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: perl-2:5.8.0-97.EL3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: perl-3:5.8.5-36.el4_5.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: perl-4:5.8.8-10.el5_0.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: perl-4:5.8.8-5.el4s1_2
View patch

Vendor Advisories (1)

redhatCVE-2007-5116Important

perl regular expression UTF parsing errors

Nov 5, 2007

References

aix.software.ibm.com / aix/efixes/security/README
docs.info.apple.com / article.html
lists.apple.com / archives/security-announce/2007/Dec/msg00002.html
lists.vmware.com / pipermail/security-announce/2008/000002.html
marc.info
bugzilla.redhat.com / show_bug.cgi
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/27479
secunia.com / advisories/27515
secunia.com / advisories/27531
Vendor Advisory
secunia.com / advisories/27546
secunia.com / advisories/27548
secunia.com / advisories/27570
secunia.com / advisories/27613
secunia.com / advisories/27756
secunia.com / advisories/27936
secunia.com / advisories/28167
secunia.com / advisories/28368
secunia.com / advisories/28387
secunia.com / advisories/28993
secunia.com / advisories/29074
secunia.com / advisories/31208
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/38270
issues.rpath.com / browse/RPL-1813
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10669
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
support.avaya.com / elmodocs2/security/ASA-2008-014.htm
www-1.ibm.com / support/docview.wss
www-1.ibm.com / support/docview.wss
debian.org / security/2007/dsa-1400
gentoo.org / security/en/glsa/glsa-200711-28.xml
ipcop.org / index.php
mandriva.com / security/advisories
Patch
novell.com / linux/security/advisories/2007_24_sr.html
openpkg.com / security/advisories/OpenPKG-SA-2007.023.html
redhat.com / support/errata/RHSA-2007-0966.html
redhat.com / support/errata/RHSA-2007-1011.html
securityfocus.com / archive/1/483563/100/0/threaded
securityfocus.com / archive/1/483584/100/0/threaded
securityfocus.com / archive/1/485936/100/0/threaded
securityfocus.com / archive/1/486859/100/0/threaded
securityfocus.com / bid/26350
ubuntu.com / usn/usn-552-1
us-cert.gov / cas/techalerts/TA07-352A.html
US Government Resource
vmware.com / security/advisories/VMSA-2008-0001.html
vupen.com / english/advisories/2007/3724
vupen.com / english/advisories/2007/4238
vupen.com / english/advisories/2007/4255
vupen.com / english/advisories/2008/0064
vupen.com / english/advisories/2008/0641