Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2017-20285: Perl libyaml before 1.30 can delete files via crafted YAML

CVE-2017-20285 · published 5 days ago
Summary

The libyaml Perl module versions earlier than 1.30, as shipped in Debian and Canonical packages, let a specially crafted YAML file cause Perl to run cleanup code (DESTROY) in any loaded class. This can be abused to delete directories or other data the file names. Upgrade libyaml-perl to version 1.30 or newer, and avoid loading YAML from untrusted sources.

What to do
  • Update debian libyaml-perl to version 1.30-1.
Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian libyaml-perl < 1.30-1
Fix: upgrade to 1.30-1
Ubuntu:16.04:LTS canonical libyaml-perl All versions
Original advisory text
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes.

A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope.

What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CWE-502Deserialization of Untrusted Data
Timeline
Published5 Oct 2026
Updated9 Oct 2026
First seen5 Oct 2026
Track software like this
Free during beta