Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2004-0377

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Perl是流行的跨平台编程语言。 ActivePerl和Larry Wall's Perl包含的'win32_stat'函数缺少正确的边界缓冲区检查,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击,可能以进程权限在系统上执行任意指令。 如果传递以反斜线符号结尾的文件名给这个'win32_stat'函数时,它拷贝数据到固定长度的缓冲区时,对字符串缺少正确的边界缓冲区检查,超长的字符串可覆盖堆栈中的控制信息,造成任意指令执行。 如果WEB包含的PERL脚本使用了这些函数,并允许用户提供路径名,就可能以WEB进程

AI Predicted 7.5 Difficulty: Easy EPSS 6.86% · P94
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2004-0377

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Perl win32_stat函数远程缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Perl是流行的跨平台编程语言。 ActivePerl和Larry Wall's Perl包含的'win32_stat'函数缺少正确的边界缓冲区检查,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击,可能以进程权限在系统上执行任意指令。 如果传递以反斜线符号结尾的文件名给这个'win32_stat'函数时,它拷贝数据到固定长度的缓冲区时,对字符串缺少正确的边界缓冲区检查,超长的字符串可覆盖堆栈中的控制信息,造成任意指令执行。 如果WEB包含的PERL脚本使用了这些函数,并允许用户提供路径名,就可能以WEB进程
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2004-0377

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-0377

登录查看更多情报信息。

Vendor Advisories for CVE-2004-0377 (2)

Mailing List Discussions for CVE-2004-0377 (2)

Other References for CVE-2004-0377 (2)

Same Patch Batch · n/a · 2004-04-06 · 11 CVEs total

CVE-2003-0648 FTE多个本地缓冲区溢出漏洞
CVE-2004-0183 TCPDump ISAKMP删除负载远程缓冲区溢出漏洞
CVE-2004-0184 TCPDump ISAKMP标识负载远程整数溢出漏洞
CVE-2004-0366 Leon J Breedt Pam-PGSQL远程SQL注入漏洞
CVE-2004-0370 FreeBSD IPv6套接口选项处理本地内存泄露漏洞
CVE-2004-0371 Heimdal Kerberos Cross-Realm信任假冒漏洞
CVE-2004-0374 Interchange远程信息泄露漏洞
CVE-2004-0376 OFTPD PORT命令畸形参数远程拒绝服务攻击漏洞
CVE-2004-0380 Microsoft Internet Explorer MT-ITS协议区域绕过漏洞
CVE-2004-0381 MySQL放弃错误报告不安全临时文件建立漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2004-0377

No comments yet


Leave a comment