---
title: "CVE-2005-3962\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2005-3962?format=md
keywords: index, follow
---

# CVE-2005-3962

Publication date 1 December 2005

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Integer overflow in the format string functionality (Perl\_sv\_vcatpvfn) in
Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory
and possibly execute arbitrary code via format string specifiers with large
values, which causes an integer wrap and leads to a buffer overflow, as
demonstrated using format string vulnerabilities in Perl applications.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| perl | 7.04 feisty | Fixed 5.8.7-10ubuntu1 |
| 6.10 edgy | Fixed 5.8.7-10ubuntu1 |
| 6.06 LTS dapper | Fixed 5.8.7-10ubuntu1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3962)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2005-3962)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2005-3962)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2005-3962)

### Related Ubuntu Security Notices (USN)

+ [USN-222-2](https://usn.ubuntu.com/USN-222-2)
+ Perl vulnerability
+ 13 December 2005

+ [USN-222-1](https://usn.ubuntu.com/USN-222-1)
+ Perl vulnerability
+ 2 December 2005

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2005-3962>
