CVE-2014-4330

Publication date 30 September 2014

Last updated 24 July 2024


Ubuntu priority

The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.

Status

Package Ubuntu Release Status
perl 15.10 wily
Not affected
15.04 vivid
Not affected
14.10 utopic
Not affected
14.04 LTS trusty
Fixed 5.18.2-2ubuntu1.1
12.04 LTS precise
Fixed 5.14.2-6ubuntu2.5
10.04 LTS lucid Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
perl

References

Related Ubuntu Security Notices (USN)

Other references