Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-4330

Опубликовано: 18 сент. 2014
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Уязвимость отказа в обслуживании (DoS) в методе "Dumper" библиотеки Data::Dumper, используемой в Perl, через Array-Reference с большим количеством вложенных Array-References

Описание

Обнаружена уязвимость в методе Dumper библиотеки Data::Dumper, используемой в Perl. Злоумышленники, зависящие от контекста, могут вызвать отказ в обслуживании (чрезмерный расход стека и аварийное завершение работы) путём передачи Array-Reference с большим количеством вложенных Array-References. Это приводит к выполнению большого числа рекурсивных вызовов функции DD_dump.

Затронутые версии ПО

  • Data::Dumper до версии 2.154
  • Perl 5.20.1 и более ранние версии

Тип уязвимости

  • Чрезмерный расход стека (stack consumption)
  • Аварийное завершение работы (crash)
  • Отказ в обслуживании (DoS)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4perlWill not fix
Red Hat Enterprise Linux 5perlWill not fix
Red Hat Enterprise Linux 6perlWill not fix
Red Hat Enterprise Linux 7perlNot affected
Red Hat Enterprise Linux 7perl-Data-DumperWill not fix
Red Hat Software Collectionsperl516-perl-Data-DumperWill not fix
Red Hat Software Collectionsrh-perl520-perl-Data-DumperNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=1139700perl-Data-Dumper: deep recursion stack overflow

EPSS

Процентиль: 43%
0.00554
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.

nvd
почти 12 лет назад

The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.

debian
почти 12 лет назад

The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 ...

suse-cvrf
почти 12 лет назад

Security update for perl

github
больше 4 лет назад

The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.

EPSS

Процентиль: 43%
0.00554
Низкий

2.6 Low

CVSS2