Описание
DBI::ProfileData versions before 1.651 for Perl do not limit the path index.
The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.
A flaw was found in DBI::ProfileData, a Perl module. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a specially crafted input. The flaw exists because the software does not properly limit the path index when processing profile dump files, which can lead to excessive memory consumption.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | perl-DBI | Fix deferred | ||
| Red Hat Enterprise Linux 6 | perl-DBI | Out of support scope | ||
| Red Hat Enterprise Linux 7 | perl-DBI | Out of support scope | ||
| Red Hat Enterprise Linux 8 | perl-DBI | Fix deferred | ||
| Red Hat Enterprise Linux 8 | perl-DBI:1.641/perl-DBI | Fix deferred | ||
| Red Hat Enterprise Linux 9 | perl-DBI | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
2.8 Low
CVSS3
Связанные уязвимости
DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.
DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.
DBI::ProfileData versions before 1.651 for Perl do not limit the path index
DBI::ProfileData versions before 1.651 for Perl do not limit the path ...
EPSS
2.8 Low
CVSS3