Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-60081

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.

A flaw was found in DBI::ProfileData, a Perl module. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a specially crafted input. The flaw exists because the software does not properly limit the path index when processing profile dump files, which can lead to excessive memory consumption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10perl-DBIFix deferred
Red Hat Enterprise Linux 6perl-DBIOut of support scope
Red Hat Enterprise Linux 7perl-DBIOut of support scope
Red Hat Enterprise Linux 8perl-DBIFix deferred
Red Hat Enterprise Linux 8perl-DBI:1.641/perl-DBIFix deferred
Red Hat Enterprise Linux 9perl-DBIFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2500005DBI: DBI::ProfileData: Denial of Service due to unbounded path index

EPSS

Процентиль: 31%
0.00379
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
18 дней назад

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.

CVSS3: 7.5
nvd
18 дней назад

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.

CVSS3: 7.5
msrc
16 дней назад

DBI::ProfileData versions before 1.651 for Perl do not limit the path index

CVSS3: 7.5
debian
18 дней назад

DBI::ProfileData versions before 1.651 for Perl do not limit the path ...

suse-cvrf
11 дней назад

Security update for perl-DBI

EPSS

Процентиль: 31%
0.00379
Низкий

2.8 Low

CVSS3