LOW · 2.1

CVE-2005-0156

Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing ...

Vulnerability Description

Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Larry WallPerl5.8.0
SgiPropack3.0
IbmAix5.2
RedhatEnterprise Linux3.0
RedhatEnterprise Linux Desktop3.0
RedhatFedora Corecore_3.0
SuseSuse Linux8.0
TrustixSecure Linux1.5
UbuntuUbuntu Linux4.1

References

FAQ

What is CVE-2005-0156?

CVE-2005-0156 is a vulnerability with a CVSS score of 2.1 (LOW). Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing ...

How severe is CVE-2005-0156?

CVE-2005-0156 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-0156?

Check the references section above for vendor advisories and patch information. Affected products include: Larry Wall Perl, Sgi Propack, Ibm Aix, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop.