CVE-2017-20230: perl-Storable: Storable for Perl: Denial of service via stack overflow in retrieve_hook function

Severity: Critical

CVSS Score: 10

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.