CVE-2004-2022

critical

Description

ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/16169

http://marc.info/?l=full-disclosure&m=108489112131099&w=2

http://marc.info/?l=full-disclosure&m=108483058514596&w=2

http://marc.info/?l=full-disclosure&m=108482796105922&w=2

http://marc.info/?l=bugtraq&m=108489894009025&w=2

http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0905.html

Details

Source: Mitre, NVD

Published: 2004-12-31

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.01927