DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade perl-DBI | Jul 14, 2026 | Jul 13, 2026 |
| Alpine Linux | — | Upgrade perl-dbi | Jul 28, 2026 | Jun 9, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-DBI-debuginfoUpgrade perl-DBI | Jun 23, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-DBI-debuginfoUpgrade perl-DBIUpgrade perl-DBI-testsUpgrade perl-DBI-debugsource | Jun 23, 2026 | Jun 9, 2026 |
| Debian | — | Upgrade libdbi-perl | Jun 16, 2026 | Jun 16, 2026 |
| Redhat_linux | — | No solution existsUpgrade perl-DBI-debuginfoUpgrade perl-DBI-debugsourceUpgrade perl-DBI | Jul 14, 2026 | Jun 9, 2026 |
| Rocky_linux | — | Upgrade perl-DBI-debuginfoUpgrade perl-DBIUpgrade perl-DBI-debugsource | Jul 16, 2026 | Jul 14, 2026 |
| Ubuntu | — | Upgrade libdbi-perl (Ubuntu Pro)Upgrade libdbi-perl | Jun 25, 2026 | Jun 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub