Impact
Prior to version 1.653, Perl's DBI library allows an attacker to load arbitrary modules via the unvalidated dbm_type and dbm_mldbm connect attributes in the DBD::DBM driver, because these values are passed directly to Perl's require without any sanitization. An attacker can supply a path or module name that points to any file, causing the application to execute code during the database connection establishment. The vulnerability is classified as CWE‑470 and can lead to arbitrary code execution in the application's context.
Affected Systems
This issue affects the Perl DBI module (specifically the DBD::DBM driver) for all releases prior to 1.653. Operating systems or distributions that ship this library via CPAN or other package managers must upgrade the DBI package to 1.653 or later to eliminate the flaw.
Risk and Exploitability
Based on the description, the vulnerability can be exploited when an application constructs a database connection request that includes untrusted values for the dbm_type or dbm_mldbm attributes. Those attributes are passed directly to Perl's require, so an attacker can supply a path or module name that points to arbitrary Perl code, which will be loaded during connection establishment. This results in arbitrary code execution within the application’s process. The description does not specify whether network access, local privilege, or other preconditions are required, so the potential scope and conditions remain uncertain. The CVSS score of 9.8 indicates a critical severity. The EPSS value is not available, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA