Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2827-1

Опубликовано: 02 окт. 2020
Источник: suse-cvrf

Описание

Security update for perl-DBI

This update for perl-DBI fixes the following issues:

  • CVE-2019-20919: Fixed a NULL profile dereference in dbi_profile (bsc#1176764).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15-ESPOS
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Module for Basesystem 15 SP1
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Server 15-LTSS
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Server for SAP Applications 15
perl-DBI-1.639-3.11.1

Описание

An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:perl-DBI-1.639-3.11.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Module for Basesystem 15 SP1:perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Server 15-LTSS:perl-DBI-1.639-3.11.1

Ссылки