Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2005-12-01T17:00:00
Updated: 2024-08-07T23:31:48.716Z
Reserved: 2005-12-01T00:00:00
Link: CVE-2005-3962
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-12-01T17:03:00.000
Modified: 2024-11-21T00:03:10.073
Link: CVE-2005-3962
Redhat