The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.
https://rt.cpan.org/Public/Bug/Display.html?id=90474
https://bugzilla.redhat.com/show_bug.cgi?id=1051108
https://bugzilla.redhat.com/show_bug.cgi?id=1030572
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734789