CVE-2014-10402
MEDIUMPerl Dbi < 1.643 - Incorrect Permission Assignment
Title source: ruleDescription
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
References (2)
Core 2
Core References
Mailing List mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/05/msg00046.html
Exploit, Patch, Third Party Advisory x_refsource_misc
https://rt.cpan.org/Public/Bug/Display.html?id=99508#txn-1911590
Scores
CVSS v3
6.1
EPSS
0.0002
EPSS Percentile
6.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Details
CWE
CWE-732
Status
published
Products (1)
perl/dbi
< 1.643
Published
Sep 16, 2020
Tracked Since
Feb 18, 2026