DBI Buffer Overflow Vulnerability in Perl

Vulnerability

A buffer overflow vulnerability has been identified in the DBI module for Perl, specifically in versions prior to 1.648. The issue arises because error messages generated when the RaiseError, PrintError, or HandleError attributes are enabled are written to a buffer limited to 200 bytes, without proper length validation. This flaw can be exploited by attackers who can manipulate the error text within an application, potentially leading to memory corruption.

Impact

Exploitation of this vulnerability can cause a stack overflow, as indicated by the CVE author.

Remediation

Users can upgrade to DBI version 1.648 or later, where this vulnerability has been fixed.

Added: Jun 9, 2026, 8:21 AM
Updated: Jun 9, 2026, 8:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.5
remediation
0.0
relevance
9.6
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.