FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-3962

This CVE name corresponds to:

Entered Topic
2006-02-15 perl, webmin, usermin -- perl format string integer wrap vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-3962
Phase Assigned(20051201)

Description

Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.

References

Source Reference
FULLDISC 20051201 Perl format string integer wrap vulnerability
BUGTRAQ 20051201 Perl format string integer wrap vulnerability
MISC http://www.dyadsecurity.com/perl-0002.html
MISC ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/007_perl.patch
MISC ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/001_perl.patch
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm
CONFIRM http://docs.info.apple.com/article.html?artnum=304829
CONFIRM http://www.ipcop.org/index.php?name=News&file=article&sid=41
APPLE APPLE-SA-2006-11-28
CONECTIVA CLSA-2006:1056
DEBIAN DSA-943
FEDORA FLSA-2006:176731
GENTOO GLSA-200512-01
HP HPSBTU02125
HP SSRT061105
MANDRAKE MDKSA-2005:225
OPENBSD [3.7] 20060105 007: SECURITY FIX: January 5, 2006
CONFIRM ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/007_perl.patch
OPENPKG OpenPKG-SA-2005.025
REDHAT RHSA-2005:880
REDHAT RHSA-2005:881
SGI 20060101-01-U
SUNALERT 102192
SUSE SUSE-SA:2005:071
SUSE SUSE-SR:2005:029
TRUSTIX TSLSA-2005-0070
UBUNTU USN-222-1
CERT TA06-333A
CERT-VN VU#948385
BID 15629
OVAL oval:org.mitre.oval:def:10598
VUPEN ADV-2005-2688
VUPEN ADV-2006-0771
VUPEN ADV-2006-2613
VUPEN ADV-2006-4750
OSVDB 21345
OSVDB 22255
OVAL oval:org.mitre.oval:def:1074
SECUNIA 17802
SECUNIA 17844
SECUNIA 17762
SECUNIA 17941
SECUNIA 17952
SECUNIA 18183
SECUNIA 18187
SECUNIA 18075
SECUNIA 18295
SECUNIA 18517
SECUNIA 17993
SECUNIA 19041
SECUNIA 18413
SECUNIA 20894
SECUNIA 23155
SECUNIA 31208