CVE-2020-14393
published 2020-09-16CVE-2020-14393: A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an…
PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.60%
44.8th percentile
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libdbi-perl | < libdbi-perl 1.643-1 (bookworm) | libdbi-perl 1.643-1 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| perl | database_interface | < 1.643 | 1.643 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g7gr-3q49-q5r9: A buffer overflow was found in perl-DBI < 1
ghsa_unreviewed·2022-05-24
CVE-2020-14393 [HIGH] CWE-787 GHSA-g7gr-3q49-q5r9: A buffer overflow was found in perl-DBI < 1
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
OSV
libdbi-perl vulnerabilities
osv·2022-02-03·CVSS 6.1
CVE-2014-10402 [MEDIUM] libdbi-perl vulnerabilities
libdbi-perl vulnerabilities
USN-5030-1 addressed vulnerabilities in Perl DBI module. This
update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the Perl DBI module incorrectly opened files outside
of the folder specified in the data source name. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2014-10402)
It was discovered that the Perl DBI module incorrectly handled certain long
strings. A local attacker could possibly use this issue to cause the DBI
module to crash, resulting in a denial of service. (CVE-2020-14393)
OSV
libdbi-perl vulnerabilities
osv·2021-08-04·CVSS 6.1
CVE-2014-10402 [MEDIUM] libdbi-perl vulnerabilities
libdbi-perl vulnerabilities
It was discovered that the Perl DBI module incorrectly opened files outside
of the folder specified in the data source name. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2014-10402)
It was discovered that the Perl DBI module incorrectly handled certain long
strings. A local attacker could possibly use this issue to cause the DBI
module to crash, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS. (CVE-2020-14393)
OSV
CVE-2020-14393: A buffer overflow was found in perl-DBI < 1
osv·2020-09-16·CVSS 7.1
CVE-2020-14393 [HIGH] CVE-2020-14393: A buffer overflow was found in perl-DBI < 1
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
Ubuntu
Perl DBI module vulnerabilities
vendor_ubuntu·2022-02-03·CVSS 6.1
CVE-2014-10402 [MEDIUM] Perl DBI module vulnerabilities
Title: Perl DBI module vulnerabilities
Summary: Several security issues were fixed in Perl DBI module.
USN-5030-1 addressed vulnerabilities in Perl DBI module. This
update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the Perl DBI module incorrectly opened files outside
of the folder specified in the data source name. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2014-10402)
It was discovered that the Perl DBI module incorrectly handled certain long
strings. A local attacker could possibly use this issue to cause the DBI
module to crash, resulting in a denial of service. (CVE-2020-14393)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Perl DBI module vulnerabilities
vendor_ubuntu·2021-08-04·CVSS 6.1
CVE-2020-14393 [MEDIUM] Perl DBI module vulnerabilities
Title: Perl DBI module vulnerabilities
Summary: Several security issues were fixed in Perl DBI module.
It was discovered that the Perl DBI module incorrectly opened files outside
of the folder specified in the data source name. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2014-10402)
It was discovered that the Perl DBI module incorrectly handled certain long
strings. A local attacker could possibly use this issue to cause the DBI
module to crash, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS. (CVE-2020-14393)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-14393: libdbi-perl - A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who ...
vendor_debian·2020·CVSS 7.1
CVE-2020-14393 [HIGH] CVE-2020-14393: libdbi-perl - A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who ...
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
Scope: local
bookworm: resolved (fixed in 1.643-1)
bullseye: resolved (fixed in 1.643-1)
forky: resolved (fixed in 1.643-1)
sid: resolved (fixed in 1.643-1)
trixie: resolved (fixed in 1.643-1)
Red Hat
perl-dbi: Buffer overflow on an overlong DBD class name
vendor_redhat·2019-08-01·CVSS 7.1
CVE-2020-14393 [HIGH] CWE-121 perl-dbi: Buffer overflow on an overlong DBD class name
perl-dbi: Buffer overflow on an overlong DBD class name
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
A buffer overflow was found in perl-DBI before version 1.643 in DBI.xs. This flaw allows a local attacker who can supply a string longer than 300 characters to cause an out-of-bounds write. The highest threat from this vulnerability is to integrity and system availability.
Package: perl-DBI (Red Hat Enterprise Linux 5) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 6) - Out of support scope
Package: perl-DBI (Red Hat Enterprise Linux 7) - Fix deferred
Package: perl-DBI (Red Hat E
No detection rules found.
Bugzilla
CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name
bugzilla·2020-09-09·CVSS 7.1
CVE-2020-14393 [HIGH] CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name
CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name
A flaw was found in perl-dbi before version 1.643. A buffer overflow on via an overlong DBD class name in dbih_setup_handle function may lead to data be written past the intended limit.
Upstream patch:
https://github.com/perl5-dbi/dbi/commit/36f2a2c5fea36d7d47d6871e420286643460e71b
Discussion:
Created perl-DBI tracking bugs for this issue:
Affects: fedora-all [bug 1877410]
---
External References:
Advisory: https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.643-...
---
Marked the CVSS score as 4.4 for products as there would only be a temporary risk to availability and low risk to data integrity due to binary protections shipped with the products.
Bugzilla
CVE-2020-14393 perl-DBI: Buffer overlfow on an overlong DBD class name [fedora-all]
bugzilla·2020-09-09·CVSS 7.1
CVE-2020-14393 [HIGH] CVE-2020-14393 perl-DBI: Buffer overlfow on an overlong DBD class name [fedora-all]
CVE-2020-14393 perl-DBI: Buffer overlfow on an overlong DBD class name [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00074.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1877409https://lists.debian.org/debian-lts-announce/2020/09/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXLKODJ7B57GITDEZZXNSHPK4VBYXYHR/https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.643http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00074.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1877409https://lists.debian.org/debian-lts-announce/2020/09/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXLKODJ7B57GITDEZZXNSHPK4VBYXYHR/https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.643
2020-09-16
Published