Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14392

Опубликовано: 31 июл. 2019
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.

An untrusted pointer dereference flaw was found in Perl-DBI before version 1.643. This flaw allows a local attacker who can manipulate calls to dbd_db_login6_sv() to cause memory corruption. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5perl-DBIOut of support scope
Red Hat Enterprise Linux 6perl-DBIOut of support scope
Red Hat Enterprise Linux 7perl-DBIFix deferred
Red Hat Enterprise Linux 8perl-DBIFix deferred
Red Hat Software Collectionsrh-perl526-perl-DBIFix deferred
Red Hat Software Collectionsrh-perl530-perl-DBIFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-822
https://bugzilla.redhat.com/show_bug.cgi?id=1877402perl-dbi: Memory corruption in XS functions when Perl stack is reallocated

EPSS

Процентиль: 37%
0.00156
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.

CVSS3: 5.5
nvd
больше 5 лет назад

An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.

CVSS3: 5.5
debian
больше 5 лет назад

An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A ...

github
больше 3 лет назад

An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.

CVSS3: 5.5
fstec
больше 5 лет назад

Уязвимость функции dbd_db_login6_sv() интерпретатора языка программирования Perl, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 37%
0.00156
Низкий

6.1 Medium

CVSS3