CVE-2014-10401
published 2020-09-11CVE-2014-10401: An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the…
PriorityP425medium6.1CVSS 3.1
AVLACLPRLUINSUCHINAL
EPSS
0.44%
36.2th percentile
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libdbi-perl | < libdbi-perl 1.633-1 (bookworm) | libdbi-perl 1.633-1 (bookworm) |
| debian | libdbi-perl | < libdbi-perl 1.643-3 (bookworm) | libdbi-perl 1.643-3 (bookworm) |
| msrc | azl3_perl-dbi_1.632-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_perl-dbi_1.643-3_on_azure_linux_3.0 | — | — |
| perl | dbi | < 1.632 | 1.632 |
| perl | dbi | <= 1.643 | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qc7v-jjp2-38r9: An issue was discovered in the DBI module through 1
ghsa_unreviewed·2022-05-17·CVSS 6.1
CVE-2014-10402 [MEDIUM] CWE-732 GHSA-qc7v-jjp2-38r9: An issue was discovered in the DBI module through 1
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
GHSA
GHSA-9347-cf5g-8j34: An issue was discovered in the DBI module before 1
ghsa_unreviewed·2022-05-17
CVE-2014-10401 [HIGH] GHSA-9347-cf5g-8j34: An issue was discovered in the DBI module before 1
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
OSV
libdbi-perl vulnerabilities
osv·2020-09-17·CVSS 5.3
CVE-2013-7490 [MEDIUM] libdbi-perl vulnerabilities
libdbi-perl vulnerabilities
It was discovered that Perl DBI module incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2013-7490)
It was discovered that Perl DBI module incorrectly handled certain files.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2014-10401)
OSV
CVE-2014-10402: An issue was discovered in the DBI module through 1
osv·2020-09-16·CVSS 6.1
CVE-2014-10402 [MEDIUM] CVE-2014-10402: An issue was discovered in the DBI module through 1
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
OSV
CVE-2014-10401: An issue was discovered in the DBI module before 1
osv·2020-09-11·CVSS 6.1
CVE-2014-10401 [MEDIUM] CVE-2014-10401: An issue was discovered in the DBI module before 1
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
Ubuntu
Perl DBI module vulnerabilities
vendor_ubuntu·2020-09-17·CVSS 5.3
CVE-2013-7490 [MEDIUM] Perl DBI module vulnerabilities
Title: Perl DBI module vulnerabilities
Summary: Several security issues were fixed in Perl DBI module.
It was discovered that Perl DBI module incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2013-7490)
It was discovered that Perl DBI module incorrectly handled certain files.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2014-10401)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl-dbi: Incomplete fix for CVE-2014-10401
vendor_redhat·2020-09-16·CVSS 6.1
CVE-2014-10402 [MEDIUM] CWE-73 perl-dbi: Incomplete fix for CVE-2014-10401
perl-dbi: Incomplete fix for CVE-2014-10401
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Package: perl-DBI (Red Hat Enterprise Linux 5) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 6) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 7) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 8) - Will not fix
Package: rh-perl526-perl-DBI (Red Hat Software Collections) - Will not fix
Package: rh-perl530-perl-DBI (Red Hat Software Collections) - Will not fix
Microsoft
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DS
vendor_msrc·2020-09-08·CVSS 6.1
CVE-2014-10402 [MEDIUM] CWE-732 An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DS
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more inf
Red Hat
perl-dbi: DBD:: File drivers open files from folders other than specifically passed
vendor_redhat·2014-10-16·CVSS 6.1
CVE-2014-10401 [MEDIUM] CWE-73 perl-dbi: DBD:: File drivers open files from folders other than specifically passed
perl-dbi: DBD:: File drivers open files from folders other than specifically passed
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
Statement: perl-DBI as shipped in Red Hat Enterprise Linux 8, rhscl-3 rh-perl526-perl-DBI and rhscl-3 rh-perl530-perl-DBI are notaffected by this flaw as the vulnerable code has already been patched in versions of perl-DBI shipped in these products.
Package: perl-DBI (Red Hat Enterprise Linux 5) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 6) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 7) - Will not fix
Package: perl-DBI (Red Hat Enterprise Linux 8) - Not affected
Package: perl-DBI (Red
Debian
CVE-2014-10401: libdbi-perl - An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drive...
vendor_debian·2014·CVSS 6.1
CVE-2014-10401 [MEDIUM] CVE-2014-10401: libdbi-perl - An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drive...
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
Scope: local
bookworm: resolved (fixed in 1.633-1)
bullseye: resolved (fixed in 1.633-1)
forky: resolved (fixed in 1.633-1)
sid: resolved (fixed in 1.633-1)
trixie: resolved (fixed in 1.633-1)
Debian
CVE-2014-10402: libdbi-perl - An issue was discovered in the DBI module through 1.643 for Perl. DBD::File driv...
vendor_debian·2014·CVSS 6.1
CVE-2014-10402 [MEDIUM] CVE-2014-10402: libdbi-perl - An issue was discovered in the DBI module through 1.643 for Perl. DBD::File driv...
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Scope: local
bookworm: resolved (fixed in 1.643-3)
bullseye: resolved (fixed in 1.643-3)
forky: resolved (fixed in 1.643-3)
sid: resolved (fixed in 1.643-3)
trixie: resolved (fixed in 1.643-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-10402 perl-dbi: Incomplete fix for CVE-2014-10401
bugzilla·2020-09-16·CVSS 6.1
CVE-2014-10402 [MEDIUM] CVE-2014-10402 perl-dbi: Incomplete fix for CVE-2014-10401
CVE-2014-10402 perl-dbi: Incomplete fix for CVE-2014-10401
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Upstream bug:
https://rt.cpan.org/Public/Bug/Display.html?id=99508#txn-1911590
Bugzilla
CVE-2014-10401 perl-dbi: DBD:: File drivers open files from folders other than specifically passed
bugzilla·2020-09-09·CVSS 6.1
CVE-2014-10401 [MEDIUM] CVE-2014-10401 perl-dbi: DBD:: File drivers open files from folders other than specifically passed
CVE-2014-10401 perl-dbi: DBD:: File drivers open files from folders other than specifically passed
A flaw was foundin perl-dbi before version. DBD::File drivers would open files from folders other than specifically passed using the f_dir attribute.
Upstream patch:
https://github.com/perl5-dbi/dbi/commit/caedc0d7d602f5b2ae5efc1b00f39efeafb7b05a
Discussion:
The fix was released by upstream in DBI-1.632.
---
Statement:
perl-DBI as shipped in Red Hat Enterprise Linux 8, rhscl-3 rh-perl526-perl-DBI and rhscl-3 rh-perl530-perl-DBI are notaffected by this flaw as the vulnerable code has already been patched in versions of perl-DBI shipped in these products.
---
External References:
Advisory: https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.632-9th-Nov-2014
Upstream Bu
https://github.com/perl5-dbi/dbi/commit/caedc0d7d602f5b2ae5efc1b00f39efeafb7b05ahttps://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.632-9th-Nov-2014https://rt.cpan.org/Public/Bug/Display.html?id=99508https://usn.ubuntu.com/4509-1/https://github.com/perl5-dbi/dbi/commit/caedc0d7d602f5b2ae5efc1b00f39efeafb7b05ahttps://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.632-9th-Nov-2014https://rt.cpan.org/Public/Bug/Display.html?id=99508https://usn.ubuntu.com/4509-1/
2020-09-11
Published