Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2016/07/27/5 | Mailing List VDB Entry |
http://cpansearch.perl.org/src/CAPTTOFU/DBD-mysql-4.029/ChangeLog | Release Notes |
https://github.com/perl5-dbi/DBD-mysql/commit/a56ae87a4c1c1fead7d09c3653905841ccccf1cc | Issue Tracking Patch |
http://www.debian.org/security/2016/dsa-3635 | Third Party Advisory |
https://rt.cpan.org/Public/Bug/Display.html?id=97625 | Issue Tracking |
http://www.openwall.com/lists/oss-security/2016/07/27/6 | Mailing List VDB Entry |
http://www.securityfocus.com/bid/92149 |
Information
Published : 2016-08-19 14:59
Updated : 2016-11-28 11:15
NVD link : CVE-2014-9906
Mitre link : CVE-2014-9906
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
debian
- debian_linux
dbd-mysql_project
- dbd-mysql