PT-2020-6257 · Perl+4 · Perl-Dbi+4

Pedro Sampaio

·

Published

2020-02-24

·

Updated

2024-06-21

·

CVE-2020-14393

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions perl-DBI versions prior to 1.643
Description The issue is related to a buffer overflow in the DBI component of the Perl programming language interpreter. This could allow an attacker to compromise data integrity and cause a denial of service. A local attacker who can supply a string longer than 300 characters could cause an out-of-bounds write.
Recommendations For versions prior to 1.643, update to version 1.643 or later to resolve the issue. As a temporary workaround, consider restricting input string lengths to prevent out-of-bounds writes.

Fix

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1326
ALT-PU-2022-3385
BDU:2021-03728
CVE-2020-14393
DLA-2386-1
MGASA-2021-0048
OPENSUSE-SU-2020:1483-1
OPENSUSE-SU-2020:1502-1
OPENSUSE-SU-2020_1483-1
OPENSUSE-SU-2020_1502-1
OPENSUSE-SU-2024:14061-1
SUSE-SU-2020:14493-1
SUSE-SU-2020:2645-1
SUSE-SU-2020:2646-1
SUSE-SU-2020:2661-1
USN-5030-1
USN-5030-2

Affected Products

Alt Linux
Linuxmint
Suse
Ubuntu
Perl-Dbi