SUSE-SA:2005:071: perl

High Nessus Plugin ID 20370


The remote host is missing a vendor-supplied security patch


The remote host is missing the patch for the advisory SUSE-SA:2005:071 (perl).

Integer overflows in the format string functionality in Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap.

This requires the attacker to be able to supply format strings to the application, which unfortunately is true for some web applications.

This issue is tracked by the Mitre CVE ID CVE-2005-3962.


Plugin Details

Severity: High

ID: 20370

File Name: suse_SA_2005_071.nasl

Version: $Revision: 1.4 $

Agent: unix

Published: 2005/12/30

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

Required KB Items: Host/SuSE/rpm-list