CVE-2005-0156 describes a buffer overflow vulnerability in the PerlIO implementation of Perl 5.8.0, specifically when installed with setuid support (sperl). This flaw allows local users to execute arbitrary code by manipulating the PERLIO_DEBUG variable and running a Perl script with a long directory path. While the CVSS score is low (2.1) with limited impact (partial integrity), its local attack vector and low complexity pose a risk to affected systems including IBM, Red Hat, and Ubuntu. Although not in CISA's KEV catalog, an ExploitDB entry (EDB-791) confirms exploit code availability, yet there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.8.0CPE matchmatch criteria | cpe:2.3:a:larry_wall:perl:5.8.0:*:*:*:*:*:*:* | ||
5.8.1CPE matchmatch criteria | cpe:2.3:a:larry_wall:perl:5.8.1:*:*:*:*:*:*:* | ||
5.8.3CPE matchmatch criteria | cpe:2.3:a:larry_wall:perl:5.8.3:*:*:*:*:*:*:* | ||
5.8.4CPE matchmatch criteria | cpe:2.3:a:larry_wall:perl:5.8.4:*:*:*:*:*:*:* | ||
5.8.4.1CPE matchmatch criteria | cpe:2.3:a:larry_wall:perl:5.8.4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.