TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-14031

HIGH
8.1

Description

Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Sereal::Encoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922. This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

Details CVE

Score CVSS v3.18.1
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurNONE
Publie3/31/2026
Derniere modification4/1/2026
Sourcenvd
Observations honeypot0

References

https://github.com/advisories/GHSA-w77f-wv46-4vcx(9b29abf9-4ab0-4765-b253-1875cd9b441e)
https://www.cve.org/CVERecord?id=CVE-2019-11922(9b29abf9-4ab0-4765-b253-1875cd9b441e)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.