Medium severity6.1NVD Advisory· Published Sep 16, 2020· Updated Jun 17, 2026
CVE-2014-10402
CVE-2014-10402
Description
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
Affected products
10cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*range: <=1.643
- (no CPE)range: <=1.643
- Perl/DBIdescription
- osv-coords7 versionspkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/perl-DBI&distro=openSUSE%20Tumbleweedpkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/perl-DBI&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5
< 1.639-lp151.3.16.1+ 6 more
- (no CPE)range: < 1.639-lp151.3.16.1
- (no CPE)range: < 1.642-lp152.2.9.1
- (no CPE)range: < 1.643-2.7
- (no CPE)range: < 1.639-3.14.1
- (no CPE)range: < 1.642-3.9.1
- (no CPE)range: < 1.628-5.9.1
- (no CPE)range: < 1.628-5.9.1
Patches
Vulnerability mechanics
References
2- rt.cpan.org/Public/Bug/Display.htmlnvdExploitPatchThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/05/msg00046.htmlnvd
News mentions
0No linked articles in our index yet.