Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14380

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 8.8

Описание

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.

A flaw was found in the DBI component for Perl. This vulnerability allows an attacker to inject and execute arbitrary code by manipulating the Profile attribute of a DBI handle. When a string is assigned to this attribute, the component processes it without proper validation, enabling the execution of unauthorized Perl code, including system commands. An attacker with control over certain inputs, such as environment variables or connection string parameters, could exploit this to achieve arbitrary code execution on the affected system. In some configurations, this could lead to remote code execution.

Отчет

This Important vulnerability in the Perl DBI component allows for arbitrary code execution due to improper validation of the Profile attribute. An attacker can exploit this by controlling inputs such as the DBI_PROFILE environment variable or DSN parameters, leading to the execution of unauthorized Perl code.

Меры по смягчению последствий

To reduce the risk of arbitrary code execution, avoid setting the DBI_PROFILE environment variable from untrusted sources. Ensure that DSN driver-attribute clauses, particularly those used with dbi:Driver(Profile=>SPEC):db, are not populated with unvalidated or untrusted input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10perl-DBIAffected
Red Hat Enterprise Linux 6perl-DBIOut of support scope
Red Hat Enterprise Linux 7perl-DBIAffected
Red Hat Enterprise Linux 8perl-DBIAffected
Red Hat Enterprise Linux 8perl-DBI:1.641/perl-DBIAffected
Red Hat Enterprise Linux 9perl-DBIAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2497915DBI: DBI: Arbitrary code execution via caller-influenced Profile attribute

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.

CVSS3: 8.8
nvd
около 1 месяца назад

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.

CVSS3: 8.8
msrc
около 1 месяца назад

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile

CVSS3: 8.8
debian
около 1 месяца назад

DBI versions before 1.650 for Perl are vulnerable to code injection vi ...

suse-cvrf
около 1 месяца назад

Security update for perl-DBI

8.8 High

CVSS3