Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-20230

Опубликовано: 21 апр. 2026
Источник: debian

Описание

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
perlfixed5.28.0-3package
libstorable-perlremovedpackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/39144694/

  • https://github.com/Perl/perl5/issues/15831

  • https://github.com/Perl/perl5/commit/a258c17c6937f79529c8319a829310e09cdbd216 (v5.27.9)

Связанные уязвимости

CVSS3: 10
ubuntu
4 месяца назад

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

CVSS3: 6.5
redhat
4 месяца назад

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

CVSS3: 10
nvd
4 месяца назад

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

msrc
4 месяца назад

Storable versions before 3.05 for Perl has a stack overflow

suse-cvrf
4 месяца назад

Security update for perl