Ubuntu Security Notice 5030-2 - USN-5030-1 addressed vulnerabilities in Perl DBI module. This update provides the corresponding updates for Ubuntu 16.04 ESM. It was discovered that the Perl DBI module incorrectly opened files outside of the folder specified in the data source name. A remote attacker could possibly use this issue to obtain sensitive information.
4156488823a7bad9ce607b22c08fb929d15f81dacd19585771c178426fe8c2b3
==========================================================================
Ubuntu Security Notice USN-5030-2
February 03, 2022
libdbi-perl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 ESM
Summary:
Several security issues were fixed in Perl DBI module.
Software Description:
- libdbi-perl: Perl Database Interface (DBI)
Details:
USN-5030-1 addressed vulnerabilities in Perl DBI module. This
update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the Perl DBI module incorrectly opened files
outside of the folder specified in the data source name. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2014-10402)
It was discovered that the Perl DBI module incorrectly handled certain
long strings. A local attacker could possibly use this issue to cause
the DBI module to crash, resulting in a denial of service. (CVE-2020-14393)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 ESM:
libdbi-perl 1.634-1ubuntu0.2+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5030-2
https://ubuntu.com/security/notices/USN-5030-1
CVE-2014-10402, CVE-2020-14393