Description

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

INFO

Published Date :

2026-04-21T15:26:18.216Z

Last Modified :

2026-04-21T18:22:25.354Z

Source :

CPANSec
AFFECTED PRODUCTS

The following products are affected by CVE-2017-20230 vulnerability.

Vendors Products
Nwclark
  • Storable

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact