Vulnerability Name: | CVE-2004-2022 (CCN-16169) | ||||||||
Assigned: | 2004-05-17 | ||||||||
Published: | 2004-05-17 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. Note: it is unclear whether this bug is in Perl or the OS API that is used by Perl. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, May 17 2004 - 15:23:56 CDT Buffer Overflow in ActivePerl ? Source: CCN Type: Full-Disclosure Mailing List, Mon May 17 2004 - 17:44:47 CDT Re: [Full-Disclosure] Buffer Overflow in ActivePerl ? Source: FULLDISC Type: UNKNOWN 20040518 Re[2]: [Full-Disclosure] Buffer Overflow in ActivePerl ? Source: CCN Type: Full-Disclosure Mailing List, Tue May 18 2004 - 04:03:40 CDT Re: Buffer Overflow in ActivePerl? Source: MITRE Type: CNA CVE-2004-2022 Source: BUGTRAQ Type: UNKNOWN 20040518 RE: [Full-Disclosure] Re: Buffer Overflow in ActivePerl ? Source: FULLDISC Type: UNKNOWN 20040517 Buffer Overflow in ActivePerl ? Source: FULLDISC Type: UNKNOWN 20040517 RE: Buffer Overflow in ActivePerl ? Source: FULLDISC Type: UNKNOWN 20040518 Re: Buffer Overflow in ActivePerl ? Source: MISC Type: Exploit http://www.oliverkarow.de/research/ActivePerlSystemBOF.txt Source: CCN Type: OSVDB ID: 16903 ActivePerl for Win32 System Function Long Argument Local DoS Source: MISC Type: Exploit http://www.perlmonks.org/index.pl?node_id=354145 Source: BID Type: Exploit 10375 Source: CCN Type: BID-10375 Multiple Perl Implementation System Function Call Buffer Overflow Vulnerability Source: XF Type: UNKNOWN perl-system-bo(16169) Source: XF Type: UNKNOWN perl-system-bo(16169) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |