OSVDB ID: 21345

Title: Perl Explicit Format Parameter Index Overflow

Info

Disclosure

Dec 01, 2005

Discovery

Sep 23, 2005

Dates

Exploit

Unknown

Solution

Unknown

Description

Perl contains a flaw that when handling a format string containing an explicit format parameter index that exceeds INT_MAX which can result in an illegal memory access. With a specially crafted request, an attacker can cause the crash of a Perl application resulting in a loss of availability.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Dyad Security has released an unofficial patch to address this vulnerability.

Products

Perl

Perl

5.9.2
5.8.7
5.8.6

References

Credit

  • Jack Louis - Dyad Security


Direct URL: http://osvdb.org/21345