An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libdbi-perl | Sep 30, 2020 | Sep 17, 2020 |
| Huawei Euleros 2_0_sp2 | — | — | Nov 3, 2020 | Sep 17, 2020 |
| Huawei Euleros 2_0_sp3 | — | — | Jan 20, 2021 | Sep 17, 2020 |
| Huawei Euleros 2_0_sp5 | — | — | Dec 16, 2020 | Sep 17, 2020 |
| Huawei Euleros 2_0_sp8 | — | — | Nov 3, 2020 | Sep 17, 2020 |
| Huawei Euleros 2_0_sp9 | — | — | Oct 13, 2020 | Sep 17, 2020 |
| Oracle Solaris | — | Upgrade library/perl-5/database-522 to version 1.643-11.4.28.0.1.82.1 on Solaris 11.4Upgrade library/perl-5/database to version 1.643-11.4.28.0.1.82.1 on Solaris 11.4Upgrade library/perl-5/database-526 to version 1.643-11.4.28.0.1.82.1 on Solaris 11.4 | Jan 19, 2021 | Sep 17, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 17, 2020 |
| Suse | — | Upgrade perl-DBI | Feb 7, 2021 | Sep 17, 2020 |
| Ubuntu | — | Upgrade libdbi-perlUpgrade libdbi-perl (Ubuntu Pro) | Jun 10, 2021 | Sep 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub