CVE-2019-20919NULL Pointer Dereference in DBI

Severity
4.7MEDIUMNVD
EPSS
0.1%
top 69.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17
Latest updateMay 24

Description

An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages2 packages

NVDperl/dbi< 1.643
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 9.0, Fedora 31, Ubuntu Linux 12.04, 14.04, 16.04, 18.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f5xq-vjwc-pqqj: An issue was discovered in the DBI module before 12022-05-24
OSV
CVE-2019-20919: An issue was discovered in the DBI module before 12020-09-17
CVEList
CVE-2019-20919: An issue was discovered in the DBI module before 12020-09-17

📋Vendor Advisories

3
Ubuntu
Perl DBI module vulnerability2020-09-23
Red Hat
perl-dbi: NULL profile dereference in dbi_profile()2019-07-31
Debian
CVE-2019-20919: libdbi-perl - An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() ...2019

💬Community

2
Bugzilla
CVE-2019-20919 perl-DBI: NULL profile dereference in dbi_profile() [fedora-all]2020-09-09
Bugzilla
CVE-2019-20919 perl-dbi: NULL profile dereference in dbi_profile()2020-09-09
CVE-2019-20919 — NULL Pointer Dereference in Perl DBI | cvebase