Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-20230

Опубликовано: 21 апр. 2026
Источник: redhat
CVSS3: 6.5

Описание

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

A flaw was found in Storable for Perl. A remote attacker can exploit a vulnerability in the retrieve_hook function by crafting malicious data. This flaw occurs because the function incorrectly handles the length of class names, storing it as a signed integer but processing it as unsigned during read operations. Successful exploitation leads to a stack overflow, which can cause a denial of service.

Отчет

This is an Moderate denial of service flaw in perl-Storable. The vulnerability arises from incorrect handling of class name lengths during deserialization, which can lead to a stack overflow when processing specially crafted data. To exploit this vulnerability the attacker needs to trick the user to use a maliciously crafted data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10perl-StorableNot affected
Red Hat Enterprise Linux 7perl-StorableFix deferred
Red Hat Enterprise Linux 8perl:5.32/perl-StorableNot affected
Red Hat Enterprise Linux 8perl-StorableNot affected
Red Hat Enterprise Linux 9perl-StorableNot affected
Red Hat Hardened Imagesperl-storable-main-3.37-522.1.hum1FixedRHSA-2026:757810.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2460147perl-Storable: Storable for Perl: Denial of service via stack overflow in retrieve_hook function

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 10
ubuntu
4 месяца назад

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

CVSS3: 10
nvd
4 месяца назад

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

msrc
4 месяца назад

Storable versions before 3.05 for Perl has a stack overflow

CVSS3: 10
debian
4 месяца назад

Storable versions before 3.05 for Perl has a stack overflow. The retr ...

suse-cvrf
4 месяца назад

Security update for perl

6.5 Medium

CVSS3