Echo: libdbi-perl: security update to 1.647-1+deb13u1+e1

high Tenable Self-Hosted Container Security Plugin ID 463904

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of
profile dump files is used to allocate an array of data for the parser. An unbounded value allows an
attacker to specify a large index and consume available memory. (CVE-2026-60081)

Solution

Update the libdbi-perl library and its related packages to version 1.647-1+deb13u1+e1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-60081

Plugin Details

Severity: High

ID: 463904

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-60081

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/22/2026

Vulnerability Publication Date: 7/14/2026

Reference Information

CVE: CVE-2026-60081