[Bug 1395591] New: CVE-2016-1249 perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



https://bugzilla.redhat.com/show_bug.cgi?id=1395591

            Bug ID: 1395591
           Summary: CVE-2016-1249 perl-DBD-MySQL: Out-of-bounds read when
                    using server-side prepared statement support
           Product: Security Response
         Component: vulnerability
          Keywords: Security
          Severity: medium
          Priority: medium
          Assignee: security-response-team@xxxxxxxxxx
          Reporter: anemec@xxxxxxxxxx
                CC: briang@xxxxxxxxxx, hhorak@xxxxxxxxxx,
                    jorton@xxxxxxxxxx, jplesnik@xxxxxxxxxx,
                    kanderso@xxxxxxxxxx,
                    perl-devel@xxxxxxxxxxxxxxxxxxxxxxx,
                    perl-maint-list@xxxxxxxxxx, ppisar@xxxxxxxxxx,
                    psabata@xxxxxxxxxx




A vulnerability was discovered in perl-DBD-MySQL that can lead to an
out-of-bounds read when using server side prepared statements with an unaligned
number of placeholders in WHERE condition and output fields in SELECT
expression.

This problem is only exposed when the user uses server-side prepared statement
support, which is NOT default behavior and was turned off back for all drivers
per MySQL AB decision in 2006 due to issues with server-side prepared
statements in the server. The behavior of the driver is normally emulated.

References:

http://seclists.org/oss-sec/2016/q4/433

Upstream patch:

https://github.com/perl5-dbi/DBD-mysql/commit/793b72b1a0baa5070adacaac0e12fd995a6fbabe

-- 
You are receiving this mail because:
You are on the CC list for the bug.
_______________________________________________
perl-devel mailing list -- perl-devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to perl-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx




[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Legacy Announce]     [Fedora PHP Devel]     [Kernel Devel]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Big List of Linux Books]     [Gimp]     [Yosemite Information]
  Powered by Linux