CVE-2014-4330
published 2014-09-30CVE-2014-4330: The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack…
PriorityP410low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.55%
42.9th percentile
The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| data_dumper_project | data_dumper | <= 2.151 | — |
| debian | perl | < perl 5.20.1-1 (bookworm) | perl 5.20.1-1 (bookworm) |
| perl | perl | <= 5.20.1 | — |
| perl | perl | >= 0 < 5.20.1-1 | 5.20.1-1 |
| perl | perl | >= 0 < 5.20.1-1 | 5.20.1-1 |
| perl | perl | >= 0 < 5.20.1-1 | 5.20.1-1 |
| perl | perl | >= 0 < 5.20.1-1 | 5.20.1-1 |
| perl | perl | >= 0 < 5.18.2-2ubuntu1.1 | 5.18.2-2ubuntu1.1 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2016-03-02·CVSS 7.5
CVE-2013-7422 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Several security issues were fixed in Perl.
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
Instructions: In general, a standard system update wil
Red Hat
perl-Data-Dumper: deep recursion stack overflow
vendor_redhat·2014-09-18·CVSS 2.1
CVE-2014-4330 [LOW] CWE-674 perl-Data-Dumper: deep recursion stack overflow
perl-Data-Dumper: deep recursion stack overflow
The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.
Package: perl (Red Hat Enterprise Linux 4) - Will not fix
Package: perl (Red Hat Enterprise Linux 5) - Will not fix
Package: perl (Red Hat Enterprise Linux 6) - Will not fix
Package: perl (Red Hat Enterprise Linux 7) - Not affected
Package: perl-Data-Dumper (Red Hat Enterprise Linux 7) - Will not fix
Package: perl516-perl-Data-Dumper (Red Hat Software Collections) - Will not fix
Package: rh-perl520-perl-Data-Dumper (Red Hat Softwa
Debian
CVE-2014-4330: perl - The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earli...
vendor_debian·2014·CVSS 2.1
CVE-2014-4330 [LOW] CVE-2014-4330: perl - The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earli...
The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.
Scope: local
bookworm: resolved (fixed in 5.20.1-1)
bullseye: resolved (fixed in 5.20.1-1)
forky: resolved (fixed in 5.20.1-1)
sid: resolved (fixed in 5.20.1-1)
trixie: resolved (fixed in 5.20.1-1)
GHSA
GHSA-gxvp-m937-jg9v: The Dumper method in Data::Dumper before 2
ghsa_unreviewed·2022-05-14
CVE-2014-4330 [LOW] CWE-119 GHSA-gxvp-m937-jg9v: The Dumper method in Data::Dumper before 2
The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.
OSV
perl vulnerabilities
osv·2016-03-02·CVSS 7.5
CVE-2013-7422 [HIGH] perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
OSV
CVE-2014-4330: The Dumper method in Data::Dumper before 2
osv·2014-09-30·CVSS 2.1
CVE-2014-4330 [LOW] CVE-2014-4330: The Dumper method in Data::Dumper before 2
The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4330 perl-Data-Dumper: deep recursion stack overflow [fedora-all]
bugzilla·2014-09-22·CVSS 2.1
CVE-2014-4330 [LOW] CVE-2014-4330 perl-Data-Dumper: deep recursion stack overflow [fedora-all]
CVE-2014-4330 perl-Data-Dumper: deep recursion stack overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2014-4330 perl-Data-Dumper: deep recursion stack overflow [epel-all]
bugzilla·2014-09-22·CVSS 2.1
CVE-2014-4330 [LOW] CVE-2014-4330 perl-Data-Dumper: deep recursion stack overflow [epel-all]
CVE-2014-4330 perl-Data-Dumper: deep recursion stack overflow [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2014-4330 perl-Data-Dumper: deep recursion stack overflow
bugzilla·2014-09-09·CVSS 2.1
CVE-2014-4330 [LOW] CVE-2014-4330 perl-Data-Dumper: deep recursion stack overflow
CVE-2014-4330 perl-Data-Dumper: deep recursion stack overflow
Upstream reports that they were given a report of stack memory exhaustion
through deep recursion in the Data::Dumper extension.
Original report below:
Issue Description
During internal development a stack overflow was discovered. The cause of the
overflow lies in the Data::Dumper extension which is part of Perl-Core. By using
the "Dumper" method on a large Array-Reference which recursively contains other
Array-References, it is possible to cause many recursive calls to the DD_dump
native function and ultimately exhaust all available stack memory.
Impact
When the runtime stack grows over the maximal size, a guard page on most modern
operating systems is hit, causing the Perl interpreter to crash.
Depending on context, code ex
http://advisories.mageia.org/MGASA-2014-0406.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-September/139441.htmlhttp://packetstormsecurity.com/files/128422/Perl-5.20.1-Deep-Recursion-Stack-Overflow.htmlhttp://seclists.org/fulldisclosure/2014/Sep/84http://seclists.org/oss-sec/2014/q3/692http://secunia.com/advisories/61441http://secunia.com/advisories/61961http://www.mandriva.com/security/advisories?name=MDVSA-2015:136http://www.nntp.perl.org/group/perl.perl5.porters/2014/09/msg220118.htmlhttp://www.securityfocus.com/archive/1/533543/100/0/threadedhttp://www.securityfocus.com/bid/70142http://www.ubuntu.com/usn/USN-2916-1https://exchange.xforce.ibmcloud.com/vulnerabilities/96216https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731https://metacpan.org/pod/distribution/Data-Dumper/Changeshttps://www.lsexperts.de/advisories/lse-2014-06-10.txthttp://advisories.mageia.org/MGASA-2014-0406.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-September/139441.htmlhttp://packetstormsecurity.com/files/128422/Perl-5.20.1-Deep-Recursion-Stack-Overflow.htmlhttp://seclists.org/fulldisclosure/2014/Sep/84http://seclists.org/oss-sec/2014/q3/692http://secunia.com/advisories/61441http://secunia.com/advisories/61961http://www.mandriva.com/security/advisories?name=MDVSA-2015:136http://www.nntp.perl.org/group/perl.perl5.porters/2014/09/msg220118.htmlhttp://www.securityfocus.com/archive/1/533543/100/0/threadedhttp://www.securityfocus.com/bid/70142http://www.ubuntu.com/usn/USN-2916-1https://exchange.xforce.ibmcloud.com/vulnerabilities/96216https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731https://metacpan.org/pod/distribution/Data-Dumper/Changeshttps://www.lsexperts.de/advisories/lse-2014-06-10.txt
2014-09-30
Published