PT-2016-2701 · Debian+3 · Debian+3

Hannob

·

Published

2016-07-28

·

Updated

2017-07-01

·

CVE-2015-8949

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DBD::mysql versions prior to 4.033 01 Debian GNU/Linux (affected versions not specified)
Description The issue is related to a use-after-free vulnerability in the my login function, which can be exploited by making a call to mysql errno after my login fails. This could allow a remote attacker to have an unspecified impact.
Recommendations For DBD::mysql versions prior to 4.033 01, update to version 4.033 01 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the my login function until a patch is available. Restrict access to the mysql errno function to minimize the risk of exploitation.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1793
BDU:2016-02095
CVE-2015-8949
DLA-576-1
DSA-3635-1
MGASA-2016-0300
USN-3103-1

Affected Products

Alt Linux
Dbd::Mysql
Debian
Ubuntu