CVE-2020-14392
published 2020-09-16CVE-2020-14392: An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.58%
43.6th percentile
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libdbi-perl | < libdbi-perl 1.643-1 (bookworm) | libdbi-perl 1.643-1 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| perl | database_interface | < 1.643 | 1.643 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xm43-qc4p-9f7j: An untrusted pointer dereference flaw was found in Perl-DBI < 1
ghsa_unreviewed·2022-05-24
CVE-2020-14392 [MEDIUM] CWE-119 GHSA-xm43-qc4p-9f7j: An untrusted pointer dereference flaw was found in Perl-DBI < 1
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
OSV
CVE-2020-14392: An untrusted pointer dereference flaw was found in Perl-DBI < 1
osv·2020-09-16·CVSS 5.5
CVE-2020-14392 [MEDIUM] CVE-2020-14392: An untrusted pointer dereference flaw was found in Perl-DBI < 1
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
Ubuntu
Perl DBI module vulnerability
vendor_ubuntu·2020-09-16
CVE-2020-14392 Perl DBI module vulnerability
Title: Perl DBI module vulnerability
Summary: Perl DBI module could be made to execute arbitrary code if it received a
specially manipulated call.
It was discovered that Perl DBI module incorrectly handled certain calls.
An attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-14392: libdbi-perl - An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local att...
vendor_debian·2020·CVSS 5.5
CVE-2020-14392 [MEDIUM] CVE-2020-14392: libdbi-perl - An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local att...
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
Scope: local
bookworm: resolved (fixed in 1.643-1)
bullseye: resolved (fixed in 1.643-1)
forky: resolved (fixed in 1.643-1)
sid: resolved (fixed in 1.643-1)
trixie: resolved (fixed in 1.643-1)
Red Hat
perl-dbi: Memory corruption in XS functions when Perl stack is reallocated
vendor_redhat·2019-07-31·CVSS 5.5
CVE-2020-14392 [MEDIUM] CWE-822 perl-dbi: Memory corruption in XS functions when Perl stack is reallocated
perl-dbi: Memory corruption in XS functions when Perl stack is reallocated
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
An untrusted pointer dereference flaw was found in Perl-DBI before version 1.643. This flaw allows a local attacker who can manipulate calls to dbd_db_login6_sv() to cause memory corruption. The highest threat from this vulnerability is to system availability.
Package: perl-DBI (Red Hat Enterprise Linux 5) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 6) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 7) - Fix deferred
Package: perl-DBI (Red Hat Enterprise Linux 8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14392 perl-DBI: Memory corruption in XS functions when Perl stack is reallocated [fedora-all]
bugzilla·2020-09-09·CVSS 5.5
CVE-2020-14392 [MEDIUM] CVE-2020-14392 perl-DBI: Memory corruption in XS functions when Perl stack is reallocated [fedora-all]
CVE-2020-14392 perl-DBI: Memory corruption in XS functions when Perl stack is reallocated [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2020-14392 perl-dbi: Memory corruption in XS functions when Perl stack is reallocated
bugzilla·2020-09-09·CVSS 5.5
CVE-2020-14392 [MEDIUM] CVE-2020-14392 perl-dbi: Memory corruption in XS functions when Perl stack is reallocated
CVE-2020-14392 perl-dbi: Memory corruption in XS functions when Perl stack is reallocated
A flaw was found in perl-dbi before version 1.643. Macro ST(*) returns pointer to Perl stack. Other Perl functions which use Perl stack (e.g. eval) may reallocate Perl stack and therefore pointer returned by ST(*) macro is invalid which may lead to memory corruption.
Upstream patch:
https://github.com/perl5-dbi/dbi/commit/ea99b6aafb437db53c28fd40d5eafbe119cd66e1
Discussion:
Created perl-DBI tracking bugs for this issue:
Affects: fedora-all [bug 1877403]
---
The fix is included in DBI-1.643 upstream release.
---
External References:
Advisory: https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.643-...
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00074.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1877402https://lists.debian.org/debian-lts-announce/2020/09/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXLKODJ7B57GITDEZZXNSHPK4VBYXYHR/https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.643https://usn.ubuntu.com/4503-1/http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00074.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1877402https://lists.debian.org/debian-lts-announce/2020/09/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXLKODJ7B57GITDEZZXNSHPK4VBYXYHR/https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.643https://usn.ubuntu.com/4503-1/
2020-09-16
Published