Buffer overflow in DBI - CVE-2013-7490

 

Buffer overflow in DBI - CVE-2013-7490

Published: September 11, 2020 / Updated: September 18, 2020


Vulnerability identifier: #VU46806
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-7490
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.


Affected software

DBI
Ubuntu
libdbi-perl (Ubuntu package)

How to mitigate CVE-2013-7490

Install update from vendor's website.

DBI - update to 1.632
libdbi-perl (Ubuntu package) - update to 1.630-1ubuntu0.1~esm4

External References

Related Security Bulletins