CVE-2017-20285 - YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes
CVE ID :CVE-2017-20285
Published : Oct. 5, 2026, 7:16 a.m. | 15 minutes ago
Description :YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 5, 2026, 7:16 a.m. | 15 minutes ago
Description :YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...