vendor:
ActivePerl
by:
Indigo
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: ActivePerl
Affected Version From: All versions of ActivePerl prior to build 630 of ActivePerl 5.6.1
Affected Version To: Build 630 of ActivePerl 5.6.1
Patch Exists: YES
Related CWE: CVE-2001-0530
CPE: a:activestate:activeperl
Platforms Tested: Windows
2001
ActivePerl Remote Buffer Overflow
ActivePerl contains a remotely exploitable buffer overflow vulnerability in handling of the URL string. It is due to an unbounded string copy operation. This vulnerability allows remote attackers to gain access to the target server.
Mitigation:
Upgrade to build 630 of ActivePerl 5.6.1 or later versions. Enable the option "Check that file exists".