| Summary: | perl-DBD-mysql new use-after-free security issues (CVE-2014-9906 and CVE-2015-8949) | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, guillomovitch, mageia, sysadmin-bugs |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/695956/ | ||
| Whiteboard: | advisory, MGA5-32-OK | ||
| Source RPM: | perl-DBD-mysql-4.32.0-3.mga6.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2016-07-25 20:15:26 CEST
David Walser
2016-07-25 20:15:39 CEST
CC:
(none) =>
guillomovitch, mageia
David Walser
2016-07-25 20:16:05 CEST
Whiteboard:
(none) =>
MGA5TOO CVE-2015-8949 has been assigned: http://openwall.com/lists/oss-security/2016/07/27/1 Summary:
perl-DBD-mysql new use-after-free security issue =>
perl-DBD-mysql new use-after-free security issue (CVE-2015-8949) CVE-2014-9906 assigned for an issue fixed in 4.029 (Mageia 5 has 4.028): http://openwall.com/lists/oss-security/2016/07/27/6 Commit to fix it also linked in the message above. Summary:
perl-DBD-mysql new use-after-free security issue (CVE-2015-8949) =>
perl-DBD-mysql new use-after-free security issues (CVE-2014-9906 and CVE-2015-8949) perl-DBD-mysql-4.35.0-1.mga6 uploaded for Cauldron by Guillaume. Version:
Cauldron =>
5 Debian has issued an advisory for this on July 29: https://www.debian.org/security/2016/dsa-3635 URL:
(none) =>
http://lwn.net/Vulnerabilities/695956/ Patched package submitted for Mageia 5. Advisory: ======================== Updated perl-DBD-mysql package fixes security vulnerabilities: Two use-after-free vulnerabilities were discovered in DBD::mysql. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using DBD::mysql (application crash), or potentially to execute arbitrary code with the privileges of the user running the application (CVE-2014-9906, CVE-2015-8949). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9906 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8949 https://www.debian.org/security/2016/dsa-3635 ======================== Updated packages in core/updates_testing: ======================== perl-DBD-mysql-4.28.0-3.1.mga5 from perl-DBD-mysql-4.28.0-3.1.mga5.src.rpm Assignee:
jquelin =>
qa-bugs Validating based on the update installing cleanly. Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2016-0300.html Status:
NEW =>
RESOLVED |