CVE-2017-20230
CRITICALStorable versions before 3.05 for Perl has a stack overflow
Title source: cnaDescription
Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.
References (6)
Scores
CVSS v3
10.0
EPSS
0.0003
EPSS Percentile
7.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-121
Status
published
Products (2)
NWCLARK/Storable
< 3.05
nwclark/storable
< 3.05
Published
Apr 21, 2026
Tracked Since
Apr 21, 2026