DEBIAN-CVE-2017-20285

Source
https://security-tracker.debian.org/tracker/CVE-2017-20285
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-20285.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2017-20285
Upstream
  • CVE-2017-20285
Published
2026-10-05T07:16:29Z
Modified
2026-10-06T05:00:04Z
Summary
[none]
Details

YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.

References

Affected packages

Debian:12 / libyaml-perl

Package

Name
libyaml-perl
Purl
pkg:deb/debian/libyaml-perl?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.30-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-20285.json"

Debian:13 / libyaml-perl

Package

Name
libyaml-perl
Purl
pkg:deb/debian/libyaml-perl?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.30-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-20285.json"

Debian:14 / libyaml-perl

Package

Name
libyaml-perl
Purl
pkg:deb/debian/libyaml-perl?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.30-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-20285.json"