CVE-2004-0377
idefense-040504.txt
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.
Desbordamiento de búfer en la función win32_stat de ActivePerl de ActiveState, y Perl de Larry Wall anterior a 5.8.3 permite a atacantes remotos ejecutar comandos arbitrarios mediante nombres de fichero que terminan en un carácter "" (barra invertida).
Remote exploitation of a buffer overflow in the win32_stat function of ActiveState's ActivePerl may allow arbitrary commands to be executed. No check is made on the length of the string before the copy is made allowing long strings to overwrite control information and execution of arbitrary code possible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2004-03-31 CVE Reserved
- 2004-04-05 CVE Published
- 2024-08-08 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=108118694327979&w=2 | Mailing List | |
http://public.activestate.com/cgi-bin/perlbrowse?patch=22552 | X_refsource_confirm | |
http://www.idefense.com/application/poi/display?id=93&type=vulnerabilities | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15732 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019794.html | 2017-07-11 | |
http://www.kb.cert.org/vuls/id/722414 | 2017-07-11 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Activestate Search vendor "Activestate" | Activeperl Search vendor "Activestate" for product "Activeperl" | * | - |
Affected
| ||||||
Larry Wall Search vendor "Larry Wall" | Perl Search vendor "Larry Wall" for product "Perl" | <= 5.8.3 Search vendor "Larry Wall" for product "Perl" and version " <= 5.8.3" | - |
Affected
|