PT-2026-29223 · Unknown+1 · Sereal::Encoder+1
CVE-2024-14031
·
Publicado
2026-03-31
·
Atualizado
2026-07-25
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sereal::Encoder versions 4.000 through 4.009 002
Description
Sereal::Encoder for Perl includes a vulnerable version of the Zstandard (zstd) library. A race condition exists in the one-pass compression functions of Zstandard versions prior to 1.3.8, potentially allowing an attacker to write bytes out of bounds when using an output buffer smaller than the recommended size.
Recommendations
Update Sereal::Encoder to a version that includes Zstandard 1.3.8 or later.
Exploit
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sereal::Encoder
Zstandard