CVE-2020-14393: Buffer Overflow
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
Other sources
A flaw was found in perl-dbi before version 1.643. A buffer overflow on via an overlong DBD class name in dbihsetuphandle function may lead to data be written past the intended limit.
Upstream patch:
https://github.com/perl5-dbi/dbi/commit/36f2a2c5fea36d7d47d6871e420286643460e71b
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-14393?
CVE-2020-14393 is a buffer overflow vulnerability found in perl-DBI < 1.643 in DBI.xs.
How does CVE-2020-14393 affect the service?
A local attacker who can supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
What is the severity of CVE-2020-14393?
CVE-2020-14393 has a severity value of 7.1 (high).
Which software versions are affected by CVE-2020-14393?
perl-DBI < 1.643 is affected by CVE-2020-14393.
How do I fix CVE-2020-14393?
Update perl-DBI to version 1.643 or higher to fix CVE-2020-14393.