CVE-2013-7490
published 2020-09-11CVE-2013-7490: An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
2.74%
84.5th percentile
An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | libdbi-perl | < libdbi-perl 1.633-1 (bookworm) | libdbi-perl 1.633-1 (bookworm) |
| perl | dbi | < 1.632 | 1.632 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl DBI module vulnerabilities
vendor_ubuntu·2020-09-17·CVSS 5.3
CVE-2013-7490 [MEDIUM] Perl DBI module vulnerabilities
Title: Perl DBI module vulnerabilities
Summary: Several security issues were fixed in Perl DBI module.
It was discovered that Perl DBI module incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2013-7490)
It was discovered that Perl DBI module incorrectly handled certain files.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2014-10401)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl-dbi: Risk of memory corruption with many arguments in DBI method dispatch
vendor_redhat·2014-09-21·CVSS 5.3
CVE-2013-7490 [MEDIUM] CWE-121 perl-dbi: Risk of memory corruption with many arguments in DBI method dispatch
perl-dbi: Risk of memory corruption with many arguments in DBI method dispatch
An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
Statement: perl-DBI as shipped in Red Hat Enterprise Linux 8, rhscl-3 rh-perl526-perl-DBI and rhscl-3 rh-perl530-perl-DBI are notaffected by this flaw as the vulnerable code has already been patched in versions of perl-DBI shipped in these products.
Package: perl-DBI (Red Hat Enterprise Linux 5) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 6) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 7) - Will not fix
Package: perl-DBI (Red Hat Enterprise Linux 8) - Not affected
Package: rh-perl526-perl-DBI (Red Hat Software Collections
Debian
CVE-2013-7490: libdbi-perl - An issue was discovered in the DBI module before 1.632 for Perl. Using many argu...
vendor_debian·2013·CVSS 5.3
CVE-2013-7490 [MEDIUM] CVE-2013-7490: libdbi-perl - An issue was discovered in the DBI module before 1.632 for Perl. Using many argu...
An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
Scope: local
bookworm: resolved (fixed in 1.633-1)
bullseye: resolved (fixed in 1.633-1)
forky: resolved (fixed in 1.633-1)
sid: resolved (fixed in 1.633-1)
trixie: resolved (fixed in 1.633-1)
GHSA
GHSA-g483-mcjg-g334: An issue was discovered in the DBI module before 1
ghsa_unreviewed·2022-05-05
CVE-2013-7490 [MEDIUM] CWE-119 GHSA-g483-mcjg-g334: An issue was discovered in the DBI module before 1
An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
OSV
libdbi-perl vulnerabilities
osv·2020-09-17·CVSS 5.3
CVE-2013-7490 [MEDIUM] libdbi-perl vulnerabilities
libdbi-perl vulnerabilities
It was discovered that Perl DBI module incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2013-7490)
It was discovered that Perl DBI module incorrectly handled certain files.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2014-10401)
OSV
CVE-2013-7490: An issue was discovered in the DBI module before 1
osv·2020-09-11·CVSS 5.3
CVE-2013-7490 [MEDIUM] CVE-2013-7490: An issue was discovered in the DBI module before 1
An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
No detection rules found.
No public exploits indexed.
https://github.com/perl5-dbi/dbi/commit/a8b98e988d6ea2946f5f56691d6d5ead53f65766https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.632-9th-Nov-2014https://rt.cpan.org/Public/Bug/Display.html?id=86744#txn-1880941https://usn.ubuntu.com/4509-1/https://github.com/perl5-dbi/dbi/commit/a8b98e988d6ea2946f5f56691d6d5ead53f65766https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.632-9th-Nov-2014https://rt.cpan.org/Public/Bug/Display.html?id=86744#txn-1880941https://usn.ubuntu.com/4509-1/
2020-09-11
Published