CVE-2005-3962
Summary
| CVE | CVE-2005-3962 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-01 17:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.trustix.org/errata/2005/0070 | af854a3a-2127-422b-91ae-364da2661108 | www.trustix.org | |
| www.osvdb.org/22255 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| 404: Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.dyadsecurity.com | Patch, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IPCop update for perl - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Secunia - Advisories - Sun Solaris update for Perl | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Secunia - Advisories - HP Tru64 UNIX and HP Internet Express Perl Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [FLSA-2006:176731] Updated perl packages fix security issue | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | |
| Secunia - Advisories - OpenBSD update for perl | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Secunia - Advisories - Debian update for perl | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| OpenPKG: Security Advisory [OpenPKG-SA-2005.025-perl] | af854a3a-2127-422b-91ae-364da2661108 | www.openpkg.org | |
| Secunia - Advisories - Mandriva update for perl | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Secunia - Advisories - SUSE update for perl | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| patches.sgi.com/support/free/security/advisories/20060101-01-U | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | |
| APPLE-SA-2006-11-28 Security Update 2006-007 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| Debian -- Security Information -- DSA-943-1 perl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| www.osvdb.org/21345 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| Secunia - Advisories - Red Hat update for perl | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Secunia - Advisories - Perl Explicit Format Parameter Index Integer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| US-CERT Vulnerability Note VU#948385 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Fedora update for perl - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| '[Full-disclosure] Perl format string integer wrap vulnerability' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| #102192: Integer Overflow Vulnerability in Perl May Lead to Application Crash or Code Execution | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| About the security content of Security Update 2006-007 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | |
| 1. Overview: | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Secunia - Advisories - Red Hat update perl | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo Linux Documentation -- Perl: Format string errors can lead to code execution | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Secunia - Advisories - SGI Advanced Linux Environment Multiple Updates | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/001_perl.patch | af854a3a-2127-422b-91ae-364da2661108 | ftp.openbsd.org | |
| Secunia - Advisories - Gentoo update for perl | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/007_perl.patch | af854a3a-2127-422b-91ae-364da2661108 | ftp.openbsd.org | |
| Secunia - Advisories - Trustix update for perl | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| US-CERT Technical Cyber Security Alert TA06-333A -- Apple Releases Security Update to Address Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| USN-222-1: Perl vulnerability | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| OpenBSD 3.7 errata | af854a3a-2127-422b-91ae-364da2661108 | www.openbsd.org | |
| Ubuntu update for perl - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IPCop 1.4.21 released :: IPCop.org :: The bad packets stop here! | af854a3a-2127-422b-91ae-364da2661108 | www.ipcop.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.