Open Vulnerability and Assessment Language (OVAL)
Contact Us Downloads News July 2, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:1074 Date: 2006-03-02
Title: Perl Format String Integer Overflow Vulnerability
Description: Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.
Version: 1 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2005-3962
Family: unix
Platform(s): Sun Solaris 10 Product(s): Perl
Definition Synopsis:

OVAL is CVE Compatible