Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2017-20285: Perl libyaml before 1.30 can delete files via crafted YAML
CVE-2017-20285 · published 5 days ago
Summary
The libyaml Perl module versions earlier than 1.30, as shipped in Debian and Canonical packages, let a specially crafted YAML file cause Perl to run cleanup code (DESTROY) in any loaded class. This can be abused to delete directories or other data the file names. Upgrade libyaml-perl to version 1.30 or newer, and avoid loading YAML from untrusted sources.
What to do
- Update debian libyaml-perl to version 1.30-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | libyaml-perl |
< 1.30-1 Fix: upgrade to 1.30-1
|
| Ubuntu:16.04:LTS | canonical | libyaml-perl | All versions |
Original advisory text
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes.
A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope.
What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope.
What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
References
- https://ubuntu.com/security/CVE-2017-20285 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-20285 Third Party Advisory
- https://github.com/ingydotnet/yaml-pm/commit/471314bbdcbd62077eea32755929122aa8b...
- https://github.com/ingydotnet/yaml-pm/commit/7736f38bd02e4f9f77d5468721e3be3d7b3...
- https://github.com/ingydotnet/yaml-pm/issues/176
- https://metacpan.org/release/TINITA/YAML-1.30/changes
- https://security-tracker.debian.org/tracker/CVE-2017-20285 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/10/05/8
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CWE-502Deserialization of Untrusted Data
Timeline
Published5 Oct 2026
Updated9 Oct 2026
First seen5 Oct 2026
Sources
CVE-2017-20285 · NVD
CVE-2017-20285 · MITRE
DEBIAN-CVE-2017-20285 · OSV
UBUNTU-CVE-2017-20285 · OSV
CVE-2017-20285 · OSV
Track software like this
Free during beta