The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.
| Software | From | Fixed in |
|---|---|---|
| perl / perl | - | 5.20.1.x |
| data_dumper_project / data_dumper | - | 2.151.x |