Buffer overflow in the PerlIO implementation in Perl 5.8.0, when...
Vulnerability Description
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-0156
Credits & Attribution
No credits recorded in the NVD database.
References
- http://marc.info/?l=full-disclosure&m=110779721503111&w=2
- http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txt
- http://www.securityfocus.com/bid/12426
- http://www.redhat.com/support/errata/RHSA-2005-105.html
- http://secunia.com/advisories/14120
- http://www.trustix.org/errata/2005/0003/
- http://www.redhat.com/support/errata/RHSA-2005-103.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10803
- http://secunia.com/advisories/55314
- http://marc.info/?l=bugtraq&m=110737149402683&w=2
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001056
- http://fedoranews.org/updates/FEDORA--.shtml
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19208
- http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml
More from larry wall
View All →Affected Vendor
larry wall
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.