Join GitHub today
GitHub is home to over 40 million developers working together to host and review code, manage projects, and build software together.Sign up
Heap-buffer-over-flow in Storable::retrieve that could lead to RCE #16131
**********Build Date & Hardware**********
This is perl 5, version 27, subversion 4 (v5.27.4
Copyright 1987-2017, Larry Wall
Perl may be copied only under the terms of either the Artistic License or the
Complete documentation for Perl, including FAQ lists, should be found on
OS: Ubuntu 16.04 Desktop
On Tue, Aug 29, 2017 at 09:25:54AM -0700, Nguyen Duc Manh wrote:
This bug is still present in blead:
$ valgrind ./perl -Ilib -e'use Storable; retrieve("/tmp/crafted1")'
I don't know what the status of the various Storable WIP branches is,
On Wed, 29 Nov 2017 01:29:23 -0800, davem wrote:
As with the other Storable bug reported to the security this, we don't treat Storable issues as security issues, so I've moved this to the public queue.
This issue is fixed in my work-in-progress branch.
On Thu, 14 Dec 2017 19:16:27 -0800, tonyc wrote:
This was merged as commit 0a40680 which was included in perl 5.28.0.