OpenPKG Security Advisory
OpenPKG-SA-2005.025
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2005.025
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2005.025
Advisory Published: 2008-10-06 16:21 UTC
Issue Id (internal): OpenPKG-SI-20051203.02
Issue First Created: 2005-12-03
Issue Last Modified: 2006-11-28
Issue Revision: 05
Subject Name: Perl
Subject Summary: Practical Extraction and Reporting Language
Subject Home: http://www.perl.com/
Subject Versions: * <= 5.8.7
Vulnerability Id: CVE-2005-3962
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector: local system
Attack Impact: denial of service, arbitrary code execution
Description:
According to a security advisory from Dyad Security [0], an integer
overflow bug exists in the Perl [1] programming language. The integer
overflow is in the format string functionality (Perl_sv_vcatpvfn) of
Perl and allows attackers to overwrite arbitrary memory and possibly
execute arbitrary code via format string specifiers with large values.
References:
[0] http://www.dyadsecurity.com/perl-0002.html
[1] http://www.perl.org/
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3962
Primary Package Name: perl
Primary Package Home: http://openpkg.org/go/package/perl
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Community 2.3-SOLID perl-5.8.6-2.3.0
OpenPKG Community 2.4-SOLID perl-5.8.7-2.4.0
OpenPKG Community 2.5-SOLID perl-5.8.7-2.5.0
OpenPKG Community CURRENT perl-5.8.7-20050921
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Community 2.3-SOLID perl-5.8.6-2.3.1
OpenPKG Community 2.4-SOLID perl-5.8.7-2.4.1
OpenPKG Community 2.5-SOLID perl-5.8.7-2.5.1
OpenPKG Community CURRENT perl-5.8.7-20051203