Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-10543

25
FAUCET Score

CVE-2020-10543 is a high-severity heap-based buffer overflow vulnerability affecting Perl versions prior to 5.30.3 on 32-bit platforms, stemming from an integer overflow in nested regular expression quantifiers. This flaw impacts products from Fedora Project, openSUSE, Oracle, and Perl itself. With a CVSS score of 8.2, it is easily exploitable over the network with low complexity and no user interaction, potentially leading to a denial of service and limited integrity impact. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.30.3CPE matchmatch criteria
cpe:2.3:a:perl:perl:*:*:*:*:*:*:x86:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
15.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
12.0.0.2.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.2.0:*:*:*:*:*:*:*
12.0.0.3.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
11.33%
Probability of exploitation in next 30 days
EPSS Percentile
95.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1133 is in the 93rd percentile among its peer group of 51,551 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: perl-4:5.16.3-299.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: perl-4:5.16.3-292.el7_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: perl-4:5.16.3-292.el7_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: perl-4:5.16.3-292.el7_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: perl-4:5.16.3-294.el7_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Extended Update SupportFixed in: perl-4:5.16.3-294.el7_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: perl-4:5.26.3-419.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: perl-4:5.26.3-418.el8_2.1
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: perl:5.24/perl

Vendor Advisories (1)

redhatCVE-2020-10543Moderate

perl: heap-based buffer overflow in regular expression compiler leads to DoS

Jun 2, 2020

References

lists.opensuse.org / opensuse-security-announce/2020-06/msg00044.html
Mailing ListThird Party Advisory
github.com / Perl/perl5/blob/blead/pod/perl5303delta.pod
Third Party Advisory
github.com / perl/perl5/commit/897d1f7fd515b828e4b198d8b8bef76c6faf03ed
PatchThird Party Advisory
github.com / Perl/perl5/compare/v5.30.2...v5.30.3
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/IN3TTBO5KSGWE5IRIKDJ5JSQRH7ANNXE
security.gentoo.org / glsa/202006-03
Third Party Advisory
security.netapp.com / advisory/ntap-20200611-0001
Third Party Advisory
oracle.com / security-alerts/cpuApr2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2020.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory