CVE-2017-20230
Storable versions before 3.05 for Perl has a stack overflow.
The retrieve_hook function stored the length of the class
Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.
CRITICAL · CVSS 10
EPSS 0.00037
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0