CVE-2017-20230

CRITICAL

Storable versions before 3.05 for Perl has a stack overflow

Title source: cna

Description

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

Scores

CVSS v3 10.0
EPSS 0.0003
EPSS Percentile 7.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-121
Status published
Products (2)
NWCLARK/Storable < 3.05
nwclark/storable < 3.05
Published Apr 21, 2026
Tracked Since Apr 21, 2026