This item is a security record, machine-translated from the oss-sec feed and published by Stig Palmquist on October 5. It identifies CVE-2017-20285, in the YAML distribution for Perl, and affects versions before 1.30. The central stated fact is that a loaded document can trigger the DESTROY method of arbitrary classes. The text available in the archive is truncated, so there are no further details on impact, exploitation conditions or mitigations beyond what is quoted. The advisory lists as references the distribution page on MetaCPAN and the project's source repository. To consult and verify, open the original source indicated in the oss-sec feed, then check on MetaCPAN and in the project repository the fixed version and release notes. The relevance is supply chain: third-party libraries used in your own systems can carry this flaw without the team noticing. Rota Nacional does not fix or detect this problem in Perl libraries, and this content does not describe any platform capability.
Cyber ·
CVE-2017-20285: YAML for Perl before 1.30 can trigger DESTROY on arbitrary classes
Advisory from the CPAN Security Group, published on October 5, on YAML for Perl versions before 1.30: a loaded document can trigger the DESTROY method of arbitrary classes.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.