[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251782

 
 

909

 
 

196543

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:1449-1 -- SLES perl-DBD-mysql

ID: oval:org.secpod.oval:def:89002213Date: (C)2021-02-26   (M)2022-10-10
Class: PATCHFamily: unix




This update for perl-DBD-mysql fixes the following issues: - CVE-2017-10789: The DBD::mysql module when with mysql_ssl=1 setting enabled, means that SSL is optional , which could lead man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152. - CVE-2017-10788: The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering certain error responses from a MySQL server or a loss of a network connection to a MySQL server. The use-after-free defect was introduced by relying on incorrect Oracle mysql_stmt_close documentation and code examples

Platform:
SUSE Linux Enterprise Server 11 SP4
Product:
perl-DBD-mysql
Reference:
SUSE-SU-2018:1449-1
CVE-2017-10788
CVE-2017-10789
CVE    2
CVE-2017-10788
CVE-2017-10789
CPE    2
cpe:/a:perl:perl-DBD-mysql
cpe:/o:suse:suse_linux_enterprise_server:11:sp4

© SecPod Technologies