CVE-2020-14392
Published: August 31, 2023Last modified: August 31, 2023
Description
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 5.5 | 
| Attack Vector | LOCAL | 
| Attack complexity | LOW | 
| Privileges required | LOW | 
| User interaction | NONE | 
| Scope | UNCHANGED | 
| Confidentiality | NONE | 
| Integrity impact | NONE | 
| Availability impact | HIGH | 
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | perl-dbi | Not affected (1.643-r4) | 
| Stream | perl-dbi | Not affected (1.643-r6) | 
References
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00067.html
 - http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00074.html
 - https://bugzilla.redhat.com/show_bug.cgi?id=1877402
 - https://lists.debian.org/debian-lts-announce/2020/09/msg00026.html
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXLKODJ7B57GITDEZZXNSHPK4VBYXYHR/
 - https://lists.fedoraproject.org/archives/list/[email protected]/message/JXLKODJ7B57GITDEZZXNSHPK4VBYXYHR/
 - https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.643
 - https://usn.ubuntu.com/4503-1/