|
|
|
Vulnerability Note VU#948385
Perl contains an integer sign error in format string processing
OverviewThe Perl interpreter contains a flaw that may increase the impact of format string vulnerabilities in programs written in Perl.
I. DescriptionPerl is a programming language used in many applications and commonly used for web applications. The Perl interpreter, which interprets and executes Perl programs, contains an integer sign error in its format string processing for formatted I/O. II. ImpactAn attacker may leverage this vulnerability to increase the impact a format string vulnerability in a Perl program. This vulnerability in the Perl interpreter is not directly exploitable.III. SolutionPatch the Perl interpreter per vendor instructions.Systems Affected
References
http://www.kb.cert.org/vuls/id/946969
http://www.dyadsecurity.com/perl-0002.html
http://secunia.com/advisories/17802/
Credit
Thanks to Jack Louis of Dyad Security, Inc. for reporting this vulnerability.
This document was written by Hal Burch.
Other Information
| Date Public | 12/01/2005 |
| Date First Published | 12/06/2005 02:14:12 PM |
| Date Last Updated | 12/28/2005 |
| CERT Advisory | |
| CVE Name | CVE-2005-3962 |
| Metric | 0.00 |
| Document Revision | 25 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |