Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20919

Опубликовано: 31 июл. 2019
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5perl-DBIOut of support scope
Red Hat Enterprise Linux 6perl-DBIOut of support scope
Red Hat Enterprise Linux 7perl-DBIFix deferred
Red Hat Enterprise Linux 8perl-DBIFix deferred
Red Hat Software Collectionsrh-perl526-perl-DBIFix deferred
Red Hat Software Collectionsrh-perl530-perl-DBIFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1877405perl-dbi: NULL profile dereference in dbi_profile()

EPSS

Процентиль: 31%
0.00116
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 5 лет назад

An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.

CVSS3: 4.7
nvd
больше 5 лет назад

An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.

CVSS3: 4.7
debian
больше 5 лет назад

An issue was discovered in the DBI module before 1.643 for Perl. The h ...

suse-cvrf
больше 5 лет назад

Security update for perl-DBI

suse-cvrf
больше 5 лет назад

Security update for perl-DBI

EPSS

Процентиль: 31%
0.00116
Низкий

4.7 Medium

CVSS3