REDHAT-BUG-2497915: Code Injection
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile.
When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name.
Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands.
The Profile attribute can be set from three different sources that can carry untrusted data: the DBIPROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db.
An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DBI (Perl DBI)to a version that resolves this vulnerability.Fixed in 1.650 - Configuration
Do not set or populate the DBI handle’s Profile attribute using untrusted/caller-influenced input. Prevent untrusted data from reaching Profile via DBI_PROFILE environment variable, direct Profile attribute assignment, or DSN clauses like dbi:Driver(Profile=>...):... (including in network-exposed DBI::Gofer / DBI::ProxyServer per-request DSNs).
DBI Profile attribute = do not set from caller-influenced/untrusted data - Compensating control
If using a network-exposed DBI::Gofer / DBI::ProxyServer, ensure the per-request DSN/driver-attribute that feeds the broker host’s Profile attribute cannot be influenced by untrusted clients (e.g., enforce strict allowlisting/validation of DSN/driver attributes at the network boundary so callers cannot supply arbitrary Profile content).