Buffer Overflow Vulnerability in Sereal::Encoder for Perl
CVE-2024-14031
8.1HIGH
What is CVE-2024-14031?
Sereal::Encoder versions ranging from 4.000 to 4.009_002 for Perl are affected by a buffer overwrite vulnerability linked to its embedded Zstandard library. This flaw stems from a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8. Attackers could exploit this vulnerability by supplying an output buffer that is smaller than the recommended size, allowing them to potentially write bytes beyond the bounds of the allocated memory, leading to unintended behavior or execution of arbitrary code.
Affected Version(s)
Sereal::Encoder 4.000 <= 4.009_002
