Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2014-10402

Published: August 31, 2023Last modified: August 31, 2023

Description

An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.

Severity score breakdown

ParameterValue
Base score6.1
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSperl-dbiNot affected (1.643-r4)
Streamperl-dbiNot affected (1.643-r6)

References

ON THIS PAGE