6.2
CVE-2026-88815
- EPSS 0.21%
- Veröffentlicht 28.09.2026 16:04:22
- Zuletzt bearbeitet 30.09.2026 20:17:35
- Erkennungen
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault. This is reachable in Perl using the sql_type_cast function: my $num = 42; DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Collection URLhttps://cpan.org/modules
≫
Paket
DBI
Default Statusunaffected
Version
0
Version <
1.654
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.1 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.2 | 2.5 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-c8vq-w3wr-6979
https://github.com/perl5-dbi/dbi/commit/e5ad87e5602da995d28b4d65df222368b58d6702.patch
https://metacpan.org/release/HMBRAND/DBI-1.654/changes
http://www.openwall.com/lists/oss-security/2026/09/28/12