CVE-2017-20230
EUVD-2017-1896721.04.2026, 16:16
Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nwclark | storable | 𝑥 < 3.05 |
𝑥
= Vulnerable software versions
openSUSE / SLES Releases
openSUSE Product | |||||
|---|---|---|---|---|---|
| perl |
| ||||
| perl-32bit |
| ||||
| perl-base |
| ||||
| perl-doc |
|
Common Weakness Enumeration
References