PT-2020-6257 · Perl+4 · Perl-Dbi+4
Pedro Sampaio
·
Published
2020-02-24
·
Updated
2024-06-21
·
CVE-2020-14393
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
perl-DBI versions prior to 1.643
Description
The issue is related to a buffer overflow in the DBI component of the Perl programming language interpreter. This could allow an attacker to compromise data integrity and cause a denial of service. A local attacker who can supply a string longer than 300 characters could cause an out-of-bounds write.
Recommendations
For versions prior to 1.643, update to version 1.643 or later to resolve the issue. As a temporary workaround, consider restricting input string lengths to prevent out-of-bounds writes.
Fix
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Suse
Ubuntu
Perl-Dbi