CVE-2014-10402
published 2020-09-16CVE-2014-10402: An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the…
PriorityP426medium6.1CVSS 3.1
AVLACLPRLUINSUCHINAL
EPSS
0.49%
38.8th percentile
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libdbi-perl | < libdbi-perl 1.643-3 (bookworm) | libdbi-perl 1.643-3 (bookworm) |
| msrc | azl3_perl-dbi_1.632-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_perl-dbi_1.643-3_on_azure_linux_3.0 | — | — |
| perl | dbi | <= 1.643 | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv6.1MEDIUM
vendor_redhat7.8HIGH
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qc7v-jjp2-38r9: An issue was discovered in the DBI module through 1
ghsa_unreviewed·2022-05-17·CVSS 6.1
CVE-2014-10402 [MEDIUM] CWE-732 GHSA-qc7v-jjp2-38r9: An issue was discovered in the DBI module through 1
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
OSV
libdbi-perl vulnerabilities
osv·2022-02-03·CVSS 6.1
CVE-2014-10402 [MEDIUM] libdbi-perl vulnerabilities
libdbi-perl vulnerabilities
USN-5030-1 addressed vulnerabilities in Perl DBI module. This
update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the Perl DBI module incorrectly opened files outside
of the folder specified in the data source name. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2014-10402)
It was discovered that the Perl DBI module incorrectly handled certain long
strings. A local attacker could possibly use this issue to cause the DBI
module to crash, resulting in a denial of service. (CVE-2020-14393)
OSV
libdbi-perl vulnerabilities
osv·2021-08-04·CVSS 6.1
CVE-2014-10402 [MEDIUM] libdbi-perl vulnerabilities
libdbi-perl vulnerabilities
It was discovered that the Perl DBI module incorrectly opened files outside
of the folder specified in the data source name. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2014-10402)
It was discovered that the Perl DBI module incorrectly handled certain long
strings. A local attacker could possibly use this issue to cause the DBI
module to crash, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS. (CVE-2020-14393)
OSV
CVE-2014-10402: An issue was discovered in the DBI module through 1
osv·2020-09-16·CVSS 6.1
CVE-2014-10402 [MEDIUM] CVE-2014-10402: An issue was discovered in the DBI module through 1
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Ubuntu
Perl DBI module vulnerabilities
vendor_ubuntu·2022-02-03·CVSS 6.1
CVE-2014-10402 [MEDIUM] Perl DBI module vulnerabilities
Title: Perl DBI module vulnerabilities
Summary: Several security issues were fixed in Perl DBI module.
USN-5030-1 addressed vulnerabilities in Perl DBI module. This
update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the Perl DBI module incorrectly opened files outside
of the folder specified in the data source name. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2014-10402)
It was discovered that the Perl DBI module incorrectly handled certain long
strings. A local attacker could possibly use this issue to cause the DBI
module to crash, resulting in a denial of service. (CVE-2020-14393)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Perl DBI module vulnerabilities
vendor_ubuntu·2021-08-04·CVSS 6.1
CVE-2020-14393 [MEDIUM] Perl DBI module vulnerabilities
Title: Perl DBI module vulnerabilities
Summary: Several security issues were fixed in Perl DBI module.
It was discovered that the Perl DBI module incorrectly opened files outside
of the folder specified in the data source name. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2014-10402)
It was discovered that the Perl DBI module incorrectly handled certain long
strings. A local attacker could possibly use this issue to cause the DBI
module to crash, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS. (CVE-2020-14393)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl-dbi: Incomplete fix for CVE-2014-10401
vendor_redhat·2020-09-16·CVSS 6.1
CVE-2014-10402 [MEDIUM] CWE-73 perl-dbi: Incomplete fix for CVE-2014-10401
perl-dbi: Incomplete fix for CVE-2014-10401
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Package: perl-DBI (Red Hat Enterprise Linux 5) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 6) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 7) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 8) - Will not fix
Package: rh-perl526-perl-DBI (Red Hat Software Collections) - Will not fix
Package: rh-perl530-perl-DBI (Red Hat Software Collections) - Will not fix
Microsoft
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DS
vendor_msrc·2020-09-08·CVSS 6.1
CVE-2014-10402 [MEDIUM] CWE-732 An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DS
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more inf
Debian
CVE-2014-10402: libdbi-perl - An issue was discovered in the DBI module through 1.643 for Perl. DBD::File driv...
vendor_debian·2014·CVSS 6.1
CVE-2014-10402 [MEDIUM] CVE-2014-10402: libdbi-perl - An issue was discovered in the DBI module through 1.643 for Perl. DBD::File driv...
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Scope: local
bookworm: resolved (fixed in 1.643-3)
bullseye: resolved (fixed in 1.643-3)
forky: resolved (fixed in 1.643-3)
sid: resolved (fixed in 1.643-3)
trixie: resolved (fixed in 1.643-3)
No detection rules found.
No public exploits indexed.
2020-09-16
Published