>> Perl "Perl_sv_vcatpvfn()" Function Integer Overflow Vulnerability
Title : Perl "Perl_sv_vcatpvfn()" Function Integer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2005-2688 CVE ID : CVE-2005-3962 CWE ID : CWE-OVAL1074
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-01
Technical Description
A vulnerability has been identified in Perl, which may be exploited by attackers to cause a denial of service or potentially execute arbitrary commands. This flaw is due to an integer overflow error in the "Perl_sv_vcatpvfn()" [sv.c] function that does not properly handle format string specifiers with large values, which could be exploited by attackers, in conjunction with format string vulnerabilities present in Perl applications, to crash an affected application and possibly execute arbitrary code.