CVE-2019-20919

Description

An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.

Risk Information

Base Score
4.7
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.116

Associated Vulnerability

VulnerabilityOS Platform
Perl Database Interface (DBI) (USN-4534-1) libdbi-perl_1.634-1ubuntu0.2_i386.debLinux
Perl Database Interface (DBI) (USN-4534-1) libdbi-perl_1.634-1ubuntu0.2_amd64.debLinux
Perl Database Interface (DBI) (USN-4534-1) libdbi-perl_1.640-1ubuntu0.2_i386.debLinux
Perl Database Interface (DBI) (USN-4534-1) libdbi-perl_1.640-1ubuntu0.2_amd64.debLinux
SUSE-SU-2020:2856-1(SUSE Linux Enterprise Server 12-SP5 ) perl-DBI-1.628-5.6.1.x86_64.rpmLinux
SUSE-SU-2020:2856-1(SUSE Linux Enterprise Server 12-SP5 ) perl-DBI-debuginfo-1.628-5.6.1.x86_64.rpmLinux
SUSE-SU-2020:2856-1(SUSE Linux Enterprise Server 12-SP5 ) perl-DBI-debugsource-1.628-5.6.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234