« Volver al listado

CVE-2004-2022

Estado: ModificadaBaja (2.1)—

ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2004-2022",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2004-12-31T05:00:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0905.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=108489894009025&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=full-disclosure&m=108482796105922&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=full-disclosure&m=108483058514596&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=full-disclosure&m=108489112131099&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.oliverkarow.de/research/ActivePerlSystemBOF.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.perlmonks.org/index.pl?node_id=354145",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/10375",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16169",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0905.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=108489894009025&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=full-disclosure&m=108482796105922&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=full-disclosure&m=108483058514596&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=full-disclosure&m=108489112131099&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oliverkarow.de/research/ActivePerlSystemBOF.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.perlmonks.org/index.pl?node_id=354145",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/10375",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16169",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow.  NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl."
    }
  ],
  "lastModified": "2026-06-16T22:08:50.750",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:activestate:activeperl:5.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "946C2AD2-EAEE-473E-9A3C-827FA3D89D2F"
            },
            {
              "criteria": "cpe:2.3:a:activestate:activeperl:5.6.1.630:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4921CDAF-E4D5-4AED-8FD9-1E506105A5D1"
            },
            {
              "criteria": "cpe:2.3:a:activestate:activeperl:5.6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA1DA7BF-DAB4-47F9-BE5B-808E8FFFC83E"
            },
            {
              "criteria": "cpe:2.3:a:activestate:activeperl:5.6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5B92CD6-8E90-4737-B5E3-1AA61A030809"
            },
            {
              "criteria": "cpe:2.3:a:activestate:activeperl:5.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DA00BED-7C68-4BEA-93CE-8A064F4A8624"
            },
            {
              "criteria": "cpe:2.3:a:activestate:activeperl:5.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB52D21C-3164-40E3-80CC-3DE2F351CBC2"
            },
            {
              "criteria": "cpe:2.3:a:activestate:activeperl:5.7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "658D6331-3F95-4D93-A244-4AD60B109CD3"
            },
            {
              "criteria": "cpe:2.3:a:activestate:activeperl:5.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20B2F92E-AE6D-4C99-8835-798D52121D93"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}