CVE-2014-4330

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
30/09/2014
Last modified:
12/04/2025

Description

The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:* 5.20.1 (including)
cpe:2.3:a:data_dumper_project:data_dumper:*:*:*:*:*:*:*:* 2.151 (including)


References to Advisories, Solutions, and Tools