The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.
Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to Storable version 3.05 or newer.
Workaround
No workaround given by the vendor.
Tue, 21 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 21 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow. | |
| Title | Storable versions before 3.05 for Perl has a stack overflow | |
| Weaknesses | CWE-121 | |
| References |
|
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-04-21T16:29:10.971Z
Reserved: 2026-03-28T19:24:26.125Z
Link: CVE-2017-20230
Updated: 2026-04-21T16:28:46.584Z
Status : Awaiting Analysis
Published: 2026-04-21T16:16:18.077
Modified: 2026-04-21T17:16:19.790
Link: CVE-2017-20230
No data.
OpenCVE Enrichment
No data.