Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability

Perl is prone to a format-string vulnerability because it fails to properly handle format specifiers in formatted-printing functions.

An attacker may leverage this issue to write to arbitrary process memory, facilitating code execution in the context of the Perl interpreter process. This can result in unauthorized remote access.

Developers should treat the formatted-printing functions in Perl as equivalently vulnerable to exploits as the C library versions and should properly sanitize all data passed in the format-specifier argument.

All applications that use formatted-printing functions in an unsafe manner should be considered exploitable.







 

Privacy Statement
Copyright 2009, SecurityFocus