Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 7: MGASA-2021-0048 Moderate: perl-DBI NULL Pointer Dereference

mageia
Calendar Grey January 22, 2021
Dist Mageia Esm H88
MGASA-2021-0049 releases updates for python-requests, fixing significant vulnerabilities and performance problems in Mageia 7.
An issue was discovered in the DBI module before 1.643 for Perl

Summary

An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference. (CVE-2019-20919).
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability. (CVE-2020-14392).
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data. (CVE-2020-14393).

References

- https://bugs.mageia.org/show_bug.cgi?id=27304

- https://ubuntu.com/security/notices/USN-4503-1

- - https://ubuntu.com/security/notices/USN-4534-1

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JXLKODJ7B57GITDEZZXNSHPK4VBYXYHR/

- https://www.cve.org/CVERecord?id=CVE-2019-20919

- https://www.cve.org/CVERecord?id=CVE-2020-14392

- https://www.cve.org/CVERecord?id=CVE-2020-14393

Resolution

SRPMS

- 7/core/perl-DBI-1.642.0-1.1.mga7

Publication date: 22 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0048.html
Type: security
CVE: CVE-2019-20919, CVE-2020-14392, CVE-2020-14393

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here