CVE-2004-2022

ActivePerl - Denial of Service and Possible Remote Code Execution via Long System Command Argument

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2022. PoCs published by Oliver Karow.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in ActiveState Perl and Perl for cygwin by passing an overly long string to the system() function, potentially leading to arbitrary code execution.

Description

ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Oliver Karow · textdoswindows
https://www.exploit-db.com/exploits/24128

This exploit demonstrates a buffer overflow vulnerability in ActiveState Perl and Perl for cygwin by passing an overly long string to the system() function, potentially leading to arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ActiveState Perl, Perl for cygwin
No auth needed
Prerequisites: Perl interpreter vulnerable to the buffer overflow
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16169
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=108489112131099&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108489894009025&w=2
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=108483058514596&w=2
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=108482796105922&w=2
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10375
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0905.html

Scores

EPSS 0.0167
EPSS Percentile 73.8%

Details

Status published
Products (8)
activestate/activeperl 5.6.1
activestate/activeperl 5.6.1.630
activestate/activeperl 5.6.2
activestate/activeperl 5.6.3
activestate/activeperl 5.7.1
activestate/activeperl 5.7.2
activestate/activeperl 5.7.3
activestate/activeperl 5.8
Published Dec 31, 2004
Tracked Since Feb 18, 2026