Impact
DBI modules earlier than version 1.654 incorrectly interpret numeric values assigned to the FetchHashKeyName attribute. When fetchrow_hashref is called, the code uses the numeric value’s memory pointer directly as a string key name, which results in an invalid pointer dereference and a segmentation fault. The vulnerability leads to an application crash and potential denial of service, but does not allow arbitrary code execution or disclosure of data. The weakness is a type confusion and improper type handling identified as CWE-843.
Affected Systems
The vulnerability affects the Perl DBI module, specifically all releases prior to 1.654. Users running DBI 1.653 or earlier are impacted regardless of the database driver used, as long as the module is loaded within a Perl application. No other vendors or platforms are listed.
Risk and Exploitability
The official CVSS score is not provided, and the EPSS value is unavailable, indicating limited publicly known exploitation data. Because the crash occurs when the application calls fetchrow_hashref with a numeric FetchHashKeyName, the threat is primarily local to the environment running the affected Perl code. Adversaries could trigger the bug by supplying input that causes the attribute to be set to a numeric value, or by modifying the application code. The lack of a KEV listing and the absence of a remote exploitation path reduce the immediate risk, though the possibility of a denial of service remains significant.
OpenCVE Enrichment