CVE-2014-10402: Medium severity Perl DBI vulnerability
Published Sep 16, 2020
·Updated
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the fdir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Affected Software
3 affected componentsFixes available
Perl DBI<=1.643
Microsoft azl3 perl-DBI 1.632-1<1.632-1
1.632-1
Microsoft azl3 perl-DBI 1.643-3<1.632-1
1.632-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.632-1
Event History
Sep 16, 2020
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
Description
Sep 4, 2025
Data Sourced
via Microsoft·04:16 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·04:16 AM
Affected Software
Updated
via Microsoft·04:16 AM
Affected Software
Updated
via Microsoft·04:16 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2014-10402.
2
What is the severity level of CVE-2014-10402?
The severity level of CVE-2014-10402 is medium.
3
What software is affected by CVE-2014-10402?
The DBI module through version 1.643 for Perl is affected by CVE-2014-10402.
4
What is the CWE ID for CVE-2014-10402?
The CWE ID for CVE-2014-10402 is 732.
5
How can I fix CVE-2014-10402?
To fix CVE-2014-10402, update the DBI module to a version beyond 1.643.