[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1910 mysql-ocaml -- missing escape function

ID: oval:org.mitre.oval:def:7959Date: (C)2009-12-15   (M)2021-07-09
Class: PATCHFamily: unix




It was discovered that mysql-ocaml, OCaml bindings for MySql, was missing a function to call mysql_real_escape_string(). This is needed, because mysql_real_escape_string() honours the charset of the connection and prevents insufficient escaping, when certain multibyte character encodings are used. The added function is called real_escape() and takes the established database connection as a first argument. The old escape_string() was kept for backwards compatibility. Developers using these bindings are encouraged to adjust their code to use the new function.

Platform:
Debian 5.0
Debian 4.0
Product:
mysql-ocaml
Reference:
DSA-1910
CVE-2009-2942
CVE    1
CVE-2009-2942
CPE    2
cpe:/o:debian:debian_linux:4.x
cpe:/o:debian:debian_linux:5.x

© SecPod Technologies