PT-2014-5814 · Perl+3 · Perl 5+4

Publicado

2014-09-30

·

Atualizado

2018-10-09

·

CVE-2014-4330

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Data::Dumper versions prior to 2.154 Perl 5 versions prior to 5.20.1
Description The issue allows context-dependent attackers to cause a denial of service, resulting in stack consumption and crash, by utilizing an Array-Reference with many nested Array-References. This triggers a large number of recursive calls to the DD dump function.
Recommendations For Data::Dumper versions prior to 2.154, update to version 2.154 or later to resolve the issue. For Perl 5 versions prior to 5.20.1, update to version 5.20.1 or later to resolve the issue.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1879
CVE-2014-4330
MGASA-2014-0405
MGASA-2014-0406
MGASA-2014-0407
SUSE-RU-2015:0562-1
SUSE-SU-2014_1321-1
USN-2916-1

Produtos afetados

Alt Linux
Data::Dumper
Perl 5
Suse
Ubuntu