Out-of-Bounds Affecting perl5 package, versions [,5.21.10)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.13% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-PERL5-2317609
  • published14 Dec 2021
  • disclosed30 Sept 2014
  • creditUnknown

Introduced: 30 Sep 2014

CVE-2014-4330  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

Upgrade perl5 to version 5.21.10 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-Bounds. The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.

CVSS Scores

version 3.1