Impact
The bug occurs when a numeric Perl scalar is passed to DBI::sql_type_cast with the target type SQL_NUMERIC. Internally, sql_type_cast_svpv forwards the scalar’s string pointer and length to the function grok_number without first converting the value to a string. Numeric scalars such as integers or floating‑point numbers have no valid string pointer, so grok_number dereferences an invalid address, triggering a segmentation fault. The result is an immediate crash of the process that called DBI, causing a denial of service for that application instance.
Affected Systems
All installations of the DBI Perl module prior to version 1.654 are affected. The issue was fixed in the 1.654 release; updating to that version or later removes the vulnerability.
Risk and Exploitability
No CVSS score or EPSS data are available, and the vulnerability is not listed in the CISA KEV catalog. The attack surface requires an attacker who can cause the application to invoke DBI::sql_type_cast with a numeric value. In many scripts and web applications that use DBI, such a call is already present, so exploitation can be achieved by injecting a numeric parameter that drives the cast. The inferred attack vector is therefore a local code path that may be leveraged remotely when the application accepts untrusted input. Exploitation results in a segmentation fault, terminating the process and disrupting service, but does not directly expose arbitrary code execution.
OpenCVE Enrichment