CVE-2005-3962
published 2005-12-01CVE-2005-3962: Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly…
PriorityP422medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
1.37%
69.2th percentile
Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.8.7-9 (bookworm) | perl 5.8.7-9 (bookworm) |
| perl | perl | — | — |
| perl | perl | — | — |
| perl | perl | >= 0 < 5.8.7-9 | 5.8.7-9 |
| perl | perl | >= 0 < 5.8.7-9 | 5.8.7-9 |
| perl | perl | >= 0 < 5.8.7-9 | 5.8.7-9 |
| perl | perl | >= 0 < 5.8.7-9 | 5.8.7-9 |
| positive_software | cp | — | — |
| positive_software | cp | — | — |
| positive_software | cp | — | — |
| positive_software | cp | — | — |
| positive_software | cp | — | — |
| positive_software | cp | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl vulnerability
vendor_ubuntu·2005-12-13
CVE-2005-3962 Perl vulnerability
Title: Perl vulnerability
Summary: Perl vulnerability
USN-222-1 fixed a vulnerability in the Perl interpreter. It was
discovered that the version of USN-222-1 was not sufficient to handle
all possible cases of malformed input that could lead to arbitrary
code execution, so another update is necessary.
Original advisory:
Jack Louis of Dyad Security discovered that Perl did not
sufficiently check the explicit length argument in format strings.
Specially crafted format strings with overly large length arguments
led to a crash of the Perl interpreter or even to execution of
arbitrary attacker-defined code with the privileges of the user
running the Perl program.
However, this attack was only possible in insecure Perl programs
which use variables with user-defined values in string
interpol
Ubuntu
Perl vulnerability
vendor_ubuntu·2005-12-02
CVE-2005-3962 Perl vulnerability
Title: Perl vulnerability
Summary: Perl vulnerability
Jack Louis of Dyad Security discovered that Perl did not sufficiently
check the explicit length argument in format strings. Specially
crafted format strings with overly large length arguments led to a
crash of the Perl interpreter or even to execution of arbitrary
attacker-defined code with the privileges of the user running the Perl
program.
However, this attack was only possible in insecure Perl programs which
use variables with user-defined values in string interpolations
without checking their validity.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-12-01·CVSS 4.6
CVE-2005-3962 [MEDIUM] security flaw
security flaw
Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
Debian
CVE-2005-3962: perl - Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5...
vendor_debian·2005·CVSS 4.6
CVE-2005-3962 [MEDIUM] CVE-2005-3962: perl - Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5...
Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
Scope: local
bookworm: resolved (fixed in 5.8.7-9)
bullseye: resolved (fixed in 5.8.7-9)
forky: resolved (fixed in 5.8.7-9)
sid: resolved (fixed in 5.8.7-9)
trixie: resolved (fixed in 5.8.7-9)
GHSA
GHSA-x9vv-cmfc-4qwh: Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5
ghsa_unreviewed·2022-05-03
CVE-2005-3962 [MEDIUM] GHSA-x9vv-cmfc-4qwh: Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5
Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
GHSA
GHSA-rc8p-8p78-4qgh: Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2
ghsa_unreviewed·2022-05-01·CVSS 4.6
CVE-2005-4261 [MEDIUM] GHSA-rc8p-8p78-4qgh: Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2
Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectors, related to "a possible security flaw caused by a bug in Perl." NOTE: unless CP+ includes its own copy of Perl with CVE-2005-3962, this is a different vulnerability than CVE-2005-3962; however, there is insufficient information to be sure.
OSV
CVE-2005-3962: Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5
osv·2005-12-01·CVSS 4.6
CVE-2005-3962 [MEDIUM] CVE-2005-3962: Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5
Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3962 security flaw
bugzilla·2018-08-16·CVSS 4.6
CVE-2005-3962 [MEDIUM] CVE-2005-3962 security flaw
CVE-2005-3962 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
Bugzilla
CVE-2005-3962 Perl Format String Vulnerability
bugzilla·2005-12-31·CVSS 4.6
CVE-2005-3962 [MEDIUM] CVE-2005-3962 Perl Format String Vulnerability
CVE-2005-3962 Perl Format String Vulnerability
Description of problem: (from John Dalbec's 9-Dec posting to
fedora-legacy-list):
HIGH: Perl Format String Vulnerability
Affected:
Perl versions 5.9.2 and 5.8.6 confirmed; potentially all Perl versions
Webmin version 1.23 and prior
Description: Perl is widely used as a scripting language for a variety
of applications including web-based software. Perl contains a
vulnerability that can be triggered by passing a format specifier of the
form "%INT_MAXn". The vulnerability causes an integer variable in a Perl
function to wrap around (change its parity) that can be exploited to
execute arbitrary code. For instance, "%2147483647n" format specifier
will trigger the flaw in Perl running on 32-bit Operating Systems. Note
that the flaw can be exploit
Bugzilla
CVE-2005-3962 Perl integer overflow issue
bugzilla·2005-12-01·CVSS 4.6
CVE-2005-3962 [MEDIUM] CVE-2005-3962 Perl integer overflow issue
CVE-2005-3962 Perl integer overflow issue
+++ This bug was initially created as a clone of Bug #174683 +++
Perl integer overflow issue
There exists an integer overflow problem in Perl which can lead to a
string format issue. If a large enough integer is supplied to a
printf statement which uses the %n conversion, it may be possible to
execute arbitrary code. This problem will not be easy to remotely
exploit as a very poorly written script will first be needed.
http://marc.theaimsgroup.com/?l=full-disclosure&m=113342788118630&w=2
Doesn't Affec: RHEL2.1
This issue also affects RHEL3
-- Additional comment from [email protected] on 2005-12-01 08:39 EST --
Created an attachment (id=121682)
Proposed patch
-- Additional comment from [email protected] on 2005-12-01 12:27 EST --
Created
Bugzilla
CVE-2005-3962 Perl integer overflow issue
bugzilla·2005-12-01·CVSS 7.5
CVE-2005-3962 [HIGH] CVE-2005-3962 Perl integer overflow issue
CVE-2005-3962 Perl integer overflow issue
Perl integer overflow issue
There exists an integer overflow problem in Perl which can lead to a
string format issue. If a large enough integer is supplied to a
printf statement which uses the %n conversion, it may be possible to
execute arbitrary code. This problem will not be easy to remotely
exploit as a very poorly written script will first be needed.
http://marc.theaimsgroup.com/?l=full-disclosure&m=113342788118630&w=2
Doesn't Affec: RHEL2.1
This issue also affects FC3
Discussion:
Created attachment 121681
Proposed patch
---
Created attachment 121694
upstream patch #26240 for this issue
---
Now applying with perl-5.8.6-18 for FC-4
---
Fixed with perl-5.8.6-18 in FC-4;
perl-5.8.7-0.8.fc5 in FC-5.
---
From User-Agent: XML-RPC
per
Bugzilla
CVE-2005-3962 Perl integer overflow issue
bugzilla·2005-12-01·CVSS 4.6
CVE-2005-3962 [MEDIUM] CVE-2005-3962 Perl integer overflow issue
CVE-2005-3962 Perl integer overflow issue
Perl integer overflow issue
There exists an integer overflow problem in Perl which can lead to a
string format issue. If a large enough integer is supplied to a
printf statement which uses the %n conversion, it may be possible to
execute arbitrary code. This problem will not be easy to remotely
exploit as a very poorly written script will first be needed.
http://marc.theaimsgroup.com/?l=full-disclosure&m=113342788118630&w=2
Doesn't Affec: RHEL2.1
This issue also affects RHEL3
Discussion:
Created attachment 121682
Proposed patch
---
Created attachment 121695
upstream patch #26240 for this issue
---
Now applying to perl-5.8.5-18.RHEL4
---
Fixed with perl-5.8.5-18.RHEL4
---
Created attachment 122197
Latest upstream patch for this issue
Bugzilla
CAN-2004-0452, CAN-2004-0976, CAN-2005-0155, CAN-2005-0156, CAN-2005-0448 multiple perl vulns
bugzilla·2004-11-09
[MEDIUM] CAN-2004-0452, CAN-2004-0976, CAN-2005-0155, CAN-2005-0156, CAN-2005-0448 multiple perl vulns
CAN-2004-0452, CAN-2004-0976, CAN-2005-0155, CAN-2005-0156, CAN-2005-0448 multiple perl vulns
http://secunia.com/advisories/12991/
Multiple vulnerabilities have been reported in Perl, which can be exploited by
malicious, local users to perform certain actions on a vulnerable system with
escalated privileges.
The vulnerabilities are caused due to various scripts creating temporary files
insecurely. This can be exploited via symlink attacks to create or overwrite
arbitrary files on the system with the privileges of the user executing a
vulnerable script.
CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0976
Red Hat Bugzilla:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136325
------- Additional Comments From [email protected] 2004-12-08 09:57:28 ----
Created an atta
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/007_perl.patchftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/001_perl.patchftp://patches.sgi.com/support/free/security/advisories/20060101-01-Uhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001056http://docs.info.apple.com/article.html?artnum=304829http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.htmlhttp://marc.info/?l=full-disclosure&m=113342788118630&w=2http://secunia.com/advisories/17762http://secunia.com/advisories/17802http://secunia.com/advisories/17844http://secunia.com/advisories/17941http://secunia.com/advisories/17952http://secunia.com/advisories/17993http://secunia.com/advisories/18075http://secunia.com/advisories/18183http://secunia.com/advisories/18187http://secunia.com/advisories/18295http://secunia.com/advisories/18413http://secunia.com/advisories/18517http://secunia.com/advisories/19041http://secunia.com/advisories/20894http://secunia.com/advisories/23155http://secunia.com/advisories/31208http://sunsolve.sun.com/search/document.do?assetkey=1-26-102192-1http://support.avaya.com/elmodocs2/security/ASA-2006-081.htmhttp://www.debian.org/security/2006/dsa-943http://www.dyadsecurity.com/perl-0002.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200512-01.xmlhttp://www.ipcop.org/index.php?name=News&file=article&sid=41http://www.kb.cert.org/vuls/id/948385http://www.mandriva.com/security/advisories?name=MDKSA-2005:225http://www.novell.com/linux/security/advisories/2005_29_sr.htmlhttp://www.novell.com/linux/security/advisories/2005_71_perl.htmlhttp://www.openbsd.org/errata37.html#perlhttp://www.openpkg.org/security/OpenPKG-SA-2005.025-perl.htmlhttp://www.osvdb.org/21345http://www.osvdb.org/22255http://www.redhat.com/support/errata/RHSA-2005-880.htmlhttp://www.redhat.com/support/errata/RHSA-2005-881.htmlhttp://www.securityfocus.com/archive/1/418333/100/0/threadedhttp://www.securityfocus.com/archive/1/438726/100/0/threadedhttp://www.securityfocus.com/bid/15629http://www.trustix.org/errata/2005/0070http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlhttp://www.vupen.com/english/advisories/2005/2688http://www.vupen.com/english/advisories/2006/0771http://www.vupen.com/english/advisories/2006/2613http://www.vupen.com/english/advisories/2006/4750https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10598https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1074https://usn.ubuntu.com/222-1/https://www.redhat.com/archives/fedora-legacy-announce/2006-February/msg00008.htmlftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/007_perl.patchftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/001_perl.patchftp://patches.sgi.com/support/free/security/advisories/20060101-01-Uhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001056http://docs.info.apple.com/article.html?artnum=304829http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.htmlhttp://marc.info/?l=full-disclosure&m=113342788118630&w=2http://secunia.com/advisories/17762http://secunia.com/advisories/17802http://secunia.com/advisories/17844http://secunia.com/advisories/17941http://secunia.com/advisories/17952http://secunia.com/advisories/17993http://secunia.com/advisories/18075http://secunia.com/advisories/18183http://secunia.com/advisories/18187http://secunia.com/advisories/18295http://secunia.com/advisories/18413http://secunia.com/advisories/18517http://secunia.com/advisories/19041http://secunia.com/advisories/20894http://secunia.com/advisories/23155http://secunia.com/advisories/31208http://sunsolve.sun.com/search/document.do?assetkey=1-26-102192-1http://support.avaya.com/elmodocs2/security/ASA-2006-081.htmhttp://www.debian.org/security/2006/dsa-943http://www.dyadsecurity.com/perl-0002.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200512-01.xmlhttp://www.ipcop.org/index.php?name=News&file=article&sid=41http://www.kb.cert.org/vuls/id/948385http://www.mandriva.com/security/advisories?name=MDKSA-2005:225http://www.novell.com/linux/security/advisories/2005_29_sr.htmlhttp://www.novell.com/linux/security/advisories/2005_71_perl.htmlhttp://www.openbsd.org/errata37.html#perlhttp://www.openpkg.org/security/OpenPKG-SA-2005.025-perl.htmlhttp://www.osvdb.org/21345http://www.osvdb.org/22255http://www.redhat.com/support/errata/RHSA-2005-880.htmlhttp://www.redhat.com/support/errata/RHSA-2005-881.htmlhttp://www.securityfocus.com/archive/1/418333/100/0/threadedhttp://www.securityfocus.com/archive/1/438726/100/0/threadedhttp://www.securityfocus.com/bid/15629http://www.trustix.org/errata/2005/0070http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlhttp://www.vupen.com/english/advisories/2005/2688http://www.vupen.com/english/advisories/2006/0771http://www.vupen.com/english/advisories/2006/2613http://www.vupen.com/english/advisories/2006/4750
+ 4 more references
2005-12-01
Published