First published: Fri Sep 11 2020(Updated: )
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Perl Dbi | <1.632 | |
ubuntu/libdbi-perl | <1.630-1ubuntu0.1~ | 1.630-1ubuntu0.1~ |
ubuntu/libdbi-perl | <1.633-1 | 1.633-1 |
debian/libdbi-perl | 1.643-3 1.643-4 1.644-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-10401 is an issue discovered in the DBI module before version 1.632 for Perl.
CVE-2014-10401 allows DBD::File drivers to open files from folders other than those specifically passed via the f_dir attribute.
The severity of CVE-2014-10401 is medium with a severity value of 6.1.
To fix CVE-2014-10401 in libdbi-perl on Debian, update to version 1.642-1+deb10u2 or 1.643-3 or 1.643-4.
To fix CVE-2014-10401 in libdbi-perl on Ubuntu Trusty, update to version 1.630-1ubuntu0.1~.