A heap out-of-bounds read vulnerability exists in Sereal::Decoder for Perl versions before 5.005. The flaw resides in the decoder's handling of COPY tags within srl_read_object() and srl_read_hash() in Perl/Decoder/srl_decoder.c. When a COPY tag's target byte is re-decoded and matches the SHORT_BINARY pattern, the resulting read is not properly bounded to precede the COPY tag's own offset. This allows an [truncated]
The Sereal::Encoder Perl module, versions from 4.000 through 4.009_002, embeds a vulnerable version of the Zstandard (zstd) library. This library is susceptible to a race condition issue, identified as CVE-2019-11922, which could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used. The vulnerability has a high impact on the security of applications [truncated]
CVE-2024-14030 is a high-severity vulnerability in Sereal::Decoder versions from 4.000 through 4.009_002 for Perl, which embeds a vulnerable version of the Zstandard library. The vulnerability is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8, which could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was use [truncated]