CVE-2017-20230Disclosure(nwclark / storable)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • storable

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
storable

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-22: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-28: 104-2104-2204-28
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-212
Disclosure2
2026-04-221
General1
2026-04-281
General1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    General

    Perl CPAN CVE-2017-20230: Storable stack buffer overflow https://www.openwall.com/lists/oss-security/2026/04/21/5 CVE-2025-15638: Net::Dropbear contains vulnerable libtomcrypt https://www.openwall.com/lists/oss-security/2026/04/21/6 CVE-2026-41564: CryptX did not reseed the Crypt::PK PRNG state after forking https://www.openwall.com/lists/oss-security/2026/04/23/2

    Post summary

    The notice lists three Perl CPAN CVE entries with brief vulnerability descriptions and links to Openwall mailing list posts, but lacks specific PoC, exploit tool, patch, or active exploitation details.

    000501.0K
    4.7K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2025-15638 | CVSS 10.0 🔴 CVE-2026-40911 | CVSS 10.0 🔴 CVE-2017-20230 | CVSS 10.0 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists three high‑severity CVEs with their CVSS scores and links to a vulnerabilities page, but provides no further technical or exploitation details.

    00000345
    5.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2017-20230 Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operati… https://www.cve.org/CVERecord?id=CVE-2017-20230 ----- Traducción: CVE-2017-20230 Las… http://infoflow.cloud`

    Post summary

    The post announces a stack‑overflow vulnerability in Perl’s Storable (pre‑3.05) with technical details, but it does not provide any PoC, exploit code, or patch information.

    0000017
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2017-20230 Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operati… https://www.cve.org/CVERecord?id=CVE-2017-20230

    Post summary

    The excerpt announces CVE-2017-20230, noting a stack overflow in Perl's Storable library prior to version 3.05, without any proof‑of‑concept, exploit, or patch details.

    00000121
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnwclarkstorable-perl-

Explore more