First published: Thu Dec 01 2005(Updated: )
Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Perl Perl | =5.9.2 | |
Perl Perl | =5.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.