CVE-2005-0156
published 2005-02-07CVE-2005-0156: Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting…
PriorityP419low2.1CVSS 2.0
AVLACLAuNCNIPAN
EXPLOIT
EPSS
1.31%
67.5th percentile
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.8.4-6 (bookworm) | perl 5.8.4-6 (bookworm) |
| ibm | aix | — | — |
| ibm | aix | — | — |
| larry_wall | perl | — | — |
| larry_wall | perl | — | — |
| larry_wall | perl | — | — |
| larry_wall | perl | — | — |
| larry_wall | perl | — | — |
| larry_wall | perl | — | — |
| larry_wall | perl | — | — |
| larry_wall | perl | — | — |
| larry_wall | perl | — | — |
| larry_wall | perl | — | — |
| perl | perl | >= 0 < 5.8.4-6 | 5.8.4-6 |
| perl | perl | >= 0 < 5.8.4-6 | 5.8.4-6 |
| perl | perl | >= 0 < 5.8.4-6 | 5.8.4-6 |
| perl | perl | >= 0 < 5.8.4-6 | 5.8.4-6 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | fedora_core | — | — |
| sgi | propack | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2005-02-02
CVE-2005-0155 Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Perl vulnerabilities
Two exploitable vulnerabilities involving setuid-enabled perl scripts
have been discovered. The package "perl-suid" provides a wrapper
around perl which allows to use setuid-root perl scripts, i.e.
user-callable Perl scripts which have full root privileges.
Previous versions allowed users to overwrite arbitrary files by
setting the PERLIO_DEBUG environment variable and calling an arbitrary
setuid-root perl script. The file that PERLIO_DEBUG points to was then
overwritten by Perl debug messages. This did not allow precise control
over the file content, but could destroy important data. PERLIO_DEBUG
is now ignored for setuid scripts. (CAN-2005-0155)
In addition, calling a setuid-root perl script with a very long path
caused a buff
Red Hat
security flaw
vendor_redhat·2005-02-01·CVSS 2.1
CVE-2005-0156 [LOW] security flaw
security flaw
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
Debian
CVE-2005-0156: perl - Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with ...
vendor_debian·2005·CVSS 2.1
CVE-2005-0156 [LOW] CVE-2005-0156: perl - Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with ...
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
Scope: local
bookworm: resolved (fixed in 5.8.4-6)
bullseye: resolved (fixed in 5.8.4-6)
forky: resolved (fixed in 5.8.4-6)
sid: resolved (fixed in 5.8.4-6)
trixie: resolved (fixed in 5.8.4-6)
GHSA
GHSA-hv4j-j5rr-rmfx: Buffer overflow in the PerlIO implementation in Perl 5
ghsa_unreviewed·2022-05-01
CVE-2005-0156 [LOW] GHSA-hv4j-j5rr-rmfx: Buffer overflow in the PerlIO implementation in Perl 5
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
OSV
CVE-2005-0156: Buffer overflow in the PerlIO implementation in Perl 5
osv·2005-02-07·CVSS 2.1
CVE-2005-0156 [LOW] CVE-2005-0156: Buffer overflow in the PerlIO implementation in Perl 5
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
No detection rules found.
Bugzilla
CVE-2005-0156 security flaw
bugzilla·2018-08-16·CVSS 2.1
CVE-2005-0156 [LOW] CVE-2005-0156 security flaw
CVE-2005-0156 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
Bugzilla
CVE-2005-3651 ethereal OSPF Protocol Dissector Buffer Overflow Vulnerability
bugzilla·2006-01-04·CVSS 7.5
CVE-2005-3651 [HIGH] CVE-2005-3651 ethereal OSPF Protocol Dissector Buffer Overflow Vulnerability
CVE-2005-3651 ethereal OSPF Protocol Dissector Buffer Overflow Vulnerability
iDEFENSE discovered a buffer overflow vulnerability in Ethereal's OSPF protocol
dissector.
http://www.idefense.com/application/poi/display?id=349&type=vulnerabilities
This issue also affects RHEL2.1 and RHEL3
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0156.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001056http://fedoranews.org/updates/FEDORA--.shtmlhttp://marc.info/?l=bugtraq&m=110737149402683&w=2http://marc.info/?l=full-disclosure&m=110779721503111&w=2http://secunia.com/advisories/14120http://secunia.com/advisories/55314http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txthttp://www.gentoo.org/security/en/glsa/glsa-200502-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:031http://www.redhat.com/support/errata/RHSA-2005-103.htmlhttp://www.redhat.com/support/errata/RHSA-2005-105.htmlhttp://www.securityfocus.com/bid/12426http://www.trustix.org/errata/2005/0003/https://exchange.xforce.ibmcloud.com/vulnerabilities/19208https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10803http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001056http://fedoranews.org/updates/FEDORA--.shtmlhttp://marc.info/?l=bugtraq&m=110737149402683&w=2http://marc.info/?l=full-disclosure&m=110779721503111&w=2http://secunia.com/advisories/14120http://secunia.com/advisories/55314http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txthttp://www.gentoo.org/security/en/glsa/glsa-200502-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:031http://www.redhat.com/support/errata/RHSA-2005-103.htmlhttp://www.redhat.com/support/errata/RHSA-2005-105.htmlhttp://www.securityfocus.com/bid/12426http://www.trustix.org/errata/2005/0003/https://exchange.xforce.ibmcloud.com/vulnerabilities/19208https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10803
2005-02-07
Published