search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Perl contains an integer sign error in format string processing

Vulnerability Note VU#948385

Original Release Date: 2005-12-06 | Last Revised: 2012-08-30

Overview

The Perl interpreter contains a flaw that may increase the impact of format string vulnerabilities in programs written in Perl.

Description

Perl is a programming language used in many applications and commonly used for web applications. The Perl interpreter, which interprets and executes Perl programs, contains an integer sign error in its format string processing for formatted I/O.

Impact

An attacker may leverage this vulnerability to increase the impact a format string vulnerability in a Perl program. This vulnerability in the Perl interpreter is not directly exploitable.

Solution

Patch the Perl interpreter per vendor instructions.

Vendor Information

948385
 

CVSS Metrics

Group Score Vector
Base 0 AV:--/AC:--/Au:--/C:--/I:--/A:--
Temporal 0 E:ND/RL:ND/RC:ND
Environmental 0 CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to Jack Louis of Dyad Security, Inc. for reporting this vulnerability.

This document was written by Hal Burch.

Other Information

CVE IDs: CVE-2005-3962
Date Public: 2005-12-01
Date First Published: 2005-12-06
Date Last Updated: 2012-08-30 18:58 UTC
Document Revision: 40

Sponsored by CISA.