Email::Address module before 1.904 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via vectors related to "backtracking into the phrase," a different vulnerability than CVE-2014-0477.
Link | Tags |
---|---|
http://seclists.org/oss-sec/2014/q2/563 | mailing list |
https://github.com/rjbs/Email-Address/blob/master/Changes |