Vulnerability Details CVE-2004-2022
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.7%
CVSS Severity
CVSS v2 Score 2.1
Products affected by CVE-2004-2022
-
cpe:2.3:a:activestate:activeperl:5.6.1
-
cpe:2.3:a:activestate:activeperl:5.6.1.630
-
cpe:2.3:a:activestate:activeperl:5.6.2
-
cpe:2.3:a:activestate:activeperl:5.6.3
-
cpe:2.3:a:activestate:activeperl:5.7.1
-
cpe:2.3:a:activestate:activeperl:5.7.2
-
cpe:2.3:a:activestate:activeperl:5.7.3
-
cpe:2.3:a:activestate:activeperl:5.8