perl-dbi: DBD:: File drivers open files from folders other than specifically passed
Published Sep 11, 2020
6.1
MEDIUMCVSS 3.1
EPSS 0.44%
Description
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
perl-DBI
Out of support scope
Red Hat Enterprise Linux 6
perl-DBI
Out of support scope
Red Hat Enterprise Linux 7
perl-DBI
Will not fix
Red Hat Enterprise Linux 8
perl-DBI
Not affected
Red Hat Enterprise Linux 9
perl-DBI
Not affected
Red Hat Software Collections
rh-perl526-perl-DBI
Not affected
Red Hat Software Collections
rh-perl530-perl-DBI
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | perl-DBI | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | perl-DBI | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | perl-DBI | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | perl-DBI | Not affected | n/a |
| Red Hat Enterprise Linux 9 | perl-DBI | Not affected | n/a |
| Red Hat Software Collections | rh-perl526-perl-DBI | Not affected | n/a |
| Red Hat Software Collections | rh-perl530-perl-DBI | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
perl-DBI as shipped in Red Hat Enterprise Linux 8, rhscl-3 rh-perl526-perl-DBI and rhscl-3 rh-perl530-perl-DBI are notaffected by this flaw as the vulnerable code has already been patched in versions of perl-DBI shipped in these products.
References (8)
- https://access.redhat.com/security/cve/CVE-2014-10401 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1877444 Issue Tracking
- https://github.com/perl5-dbi/dbi/commit/caedc0d7d602f5b2ae5efc1b00f39efeafb7b05a x_refsource_MISCPatchThird Party Advisory
- https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.632-9th-Nov-2014 x_refsource_MISCRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-10401
- https://rt.cpan.org/Public/Bug/Display.html?id=99508 x_refsource_MISCThird Party Advisory
- https://usn.ubuntu.com/4509-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2014-10401
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2014-10401 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1877444 | Issue Tracking | |
| https://github.com/perl5-dbi/dbi/commit/caedc0d7d602f5b2ae5efc1b00f39efeafb7b05a | x_refsource_MISCPatchThird Party Advisory | |
| https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.632-9th-Nov-2014 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2014-10401 | ||
| https://rt.cpan.org/Public/Bug/Display.html?id=99508 | x_refsource_MISCThird Party Advisory | |
| https://usn.ubuntu.com/4509-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2014-10401 |
Change history (0)
No recorded changes yet.