{"id":"CVE-2017-20230","details":"Storable versions before 3.05 for Perl has a stack overflow.\n\nThe retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.","modified":"2026-08-07T11:31:19.978405786Z","published":"2026-04-21T16:16:18.077Z","related":["SUSE-SU-2026:1567-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:nwclark:storable:*:*:*:*:*:perl:*:*"],"extracted_events":[{"fixed":"3.05"}],"source":"CPE_RANGE","vendor_product":"nwclark:storable"},{"extracted_events":[{"fixed":"3.05"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"https://metacpan.org/release/RURBAN/Storable-3.05/changes"},{"type":"ADVISORY","url":"https://www.nntp.perl.org/group/perl.perl5.porters/2017/01/msg242533.html"},{"type":"ADVISORY","url":"https://www.nntp.perl.org/group/perl.perl5.porters/2017/01/msg242703.html"},{"type":"REPORT","url":"https://github.com/Perl/perl5/issues/15831"},{"type":"FIX","url":"https://github.com/Perl/perl5/commit/a258c17c6937f79529c8319a829310e09cdbd216.patch"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2026/04/21/5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/perl/perl5","events":[{"introduced":"0"},{"fixed":"a258c17c6937f79529c8319a829310e09cdbd216"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v5.27.8","v5.27.7","v5.27.6","v5.27.5","v5.27.3","v5.26.0","v5.27.0","v5.26.0-RC2","v5.25.11","v5.25.9","v5.25.7","v5.25.5","v5.25.4","v5.25.3","v5.24.0","v5.25.2","v5.25.0","v5.24.0-RC5","v5.24.0-RC4","v5.24.0-RC3","v5.24.0-RC2","v5.24.0-RC1","v5.23.7","v5.23.6","v5.23.4","v5.23.3","if-0.0605","v5.23.2","v5.23.1","v5.23.0","v5.22.0","v5.22.0-RC2","v5.22.0-RC1","v5.21.11","if-0.0604","v5.21.10","v5.21.9","v5.21.8","v5.21.6","v5.21.5","v5.21.4","v5.21.1","v5.21.0","v5.20.0","v5.20.0-RC1","v5.19.11","v5.19.7","v5.19.5","v5.19.3","v5.19.2","if-0.0603","v5.19.1","v5.18.0","v5.19.0","v5.18.0-RC4","v5.18.0-RC3","v5.18.0-RC2","v5.18.0-RC1","v5.17.9","v5.17.8","v5.17.7.0","v5.17.7","v5.17.6","v5.17.4","v5.17.2","v5.17.0","v5.16.0","v5.16.0-RC2","v5.16.0-RC1","v5.15.9","v5.15.5","v5.15.4","v5.15.3","v5.15.2","v5.15.1","v5.15.0","v5.14.0","v5.14.0-RC3","v5.14.0-RC2","v5.14.0-RC1","v5.13.11","v5.13.10","v5.13.9","v5.13.8","v5.13.7","v5.13.6","v5.13.5","v5.13.4","v5.13.3","v5.13.2","v5.13.1","v5.12.0","v5.13.0","v5.12.0-RC5","v5.12.0-RC4","v5.12.0-RC3","v5.12.0-RC2","v5.12.0-RC1","v5.12.0-RC0","v5.11.5","v5.11.4","v5.11.3","v5.11.1","v5.11.0","GitLive-blead","v5.10.0","perl-5.9.5","perl-5.9.4","perl-5.9.3","perl-5.9.2","perl-5.9.1","perl-5.9.0","perl-5.8.0","perl-5.7.3","perl-5.7.2","perl-5.7.1","perl-5.7.0","perl-5.6.0","perl-5.005","perl-5.003","perl-5.002_01","perl-5.002","perl-5.001n","perl-5.001","perl-5.000o","perl-5.000","perl-5a9","perl-5a2","perl-4.0.36","perl-4.0.00","perl-3.044","perl-3.000","perl-2.0","perl-1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-20230.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}