CVE-2017-20285

Source
https://cve.org/CVERecord?id=CVE-2017-20285
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-20285.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-20285
Downstream
Published
2026-10-05T07:16:29Z
Modified
2026-10-08T02:45:04Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes.

A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope.

What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.

References

Affected packages

Git / github.com/ingydotnet/yaml-pm

Affected ranges

Type
GIT
Repo
https://github.com/ingydotnet/yaml-pm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.30"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.25
0.26
0.30
0.35
0.36
0.37
0.38
0.39
0.49_01
0.49_70
0.50
0.51
0.52
0.53
0.54
0.55
0.56
0.57
0.58
0.60
0.61
0.62
0.63
0.64
0.65
0.66
0.67
0.68
0.70
0.71
0.72
0.73
0.74
0.75
0.76
0.77
0.78
0.79
0.80
0.81
0.82
0.83
0.84
0.85
0.86
0.87
0.88
0.93
0.94
0.95
0.96
0.97
0.98
0.99
1.*
1.00
1.01
1.02
1.03
1.04
1.05
1.06
1.07
1.08
1.09
1.10
1.11
1.12
1.13
1.14
1.15
1.16
1.16_001
1.16_002
1.17
1.18
1.18_001
1.19
1.19_001
1.20
1.20_001
1.20_002
1.21
1.22
1.23
1.23_003
1.24
old-yaml-pm-1.*
old-yaml-pm-1.23
v0.*
v0.89
v0.90
v0.91
v0.92

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-20285.json"