A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl-dbi | Sep 23, 2020 | Sep 16, 2020 |
| Debian | — | Upgrade libdbi-perl | Sep 30, 2020 | Sep 16, 2020 |
| Gentoo Linux | — | Upgrade dev-perl/DBI. | Sep 14, 2020 | Sep 13, 2020 |
| Huawei Euleros 2_0_sp2 | — | — | Nov 3, 2020 | Sep 16, 2020 |
| Huawei Euleros 2_0_sp3 | — | — | Jan 20, 2021 | Sep 16, 2020 |
| Huawei Euleros 2_0_sp5 | — | — | Dec 16, 2020 | Sep 16, 2020 |
| Huawei Euleros 2_0_sp8 | — | — | Nov 3, 2020 | Sep 16, 2020 |
| Huawei Euleros 2_0_sp9 | — | — | Nov 3, 2020 | Sep 16, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 16, 2020 |
| Suse | — | Upgrade perl-DBI | Sep 17, 2020 | Sep 16, 2020 |
| Ubuntu | — | Upgrade libdbi-perl (Ubuntu Pro)Upgrade libdbi-perl | Aug 5, 2021 | Sep 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub