CVE-2014-4330
CVE-2014-4330
The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://advisories.mageia.org/MGASA-2014-0406.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-September/139441.htmlhttp://packetstormsecurity.com/files/128422/Perl-5.20.1-Deep-Recursion-Stack-Overflow.htmlhttp://seclists.org/fulldisclosure/2014/Sep/84http://seclists.org/oss-sec/2014/q3/692http://secunia.com/advisories/61441http://secunia.com/advisories/61961https://exchange.xforce.ibmcloud.com/vulnerabilities/96216https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731https://metacpan.org/pod/distribution/Data-Dumper/Changeshttps://www.lsexperts.de/advisories/lse-2014-06-10.txthttp://www.mandriva.com/security/advisories?name=MDVSA-2015:136