CVE-2017-20285: YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes.
A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope.
What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YAML for Perlto a version that resolves this vulnerability.Fixed in 1.30
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An attacker must be able to cause the application to load a YAML document. The process must also have a class loaded whose DESTROY method produces a harmful effect when invoked with attacker-supplied object fields.
What is a concrete impact example?
If File::Temp::Dir from core Perl is loaded, a crafted perl/hash:Class tag can create an object whose destruction deletes the directory tree named in the YAML document.
How can I tell whether an application is exposed to the documented impact?
Check whether it uses a YAML version before 1.30 and loads YAML from an attacker-influenced source. Also identify classes loaded in the process that implement DESTROY, particularly File::Temp::Dir.