Security Advisories (1)
CVE-2021-24032 (2021-03-04)

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

Changes for version 4.020

  • Fix "panic: free from wrong pool" errors on threaded builds. This error is only visible on DEBUGGING perls however it exists regardless. If you are using a threaded build upgrade to this! Thanks to Andreas J. Koenig for finding the bug, and Nicholas Clark for suggesting valgrind to debug and fix it.

Modules

Fast, compact, powerful binary serialization

Provides

in lib/Sereal/Encoder/Constants.pm