USN-7417-1
Dashboard / Vulnerabilities / USN-7417-1
USN-7417-1
Summary: libdbd-mysql-perl vulnerabilities
Details: It was discovered that libdbd-mysql-perl did not correctly handle certain SQL queries. An attacker could possibly use this issue to cause a denial of service. (CVE-2016-1249) It was discovered that libdbd-mysql-perl did not correctly handle certain memory operations, which could lead to a use-after-free vulnerability. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2016-1251, CVE-2017-10788) It was discovered that libdbd-mysql-perl did not properly enforce SSL connections depending on the mysql_ssl setting. A machine-in-the-middle attacker could possibly use this issue to spoof servers. (CVE-2017-10789)
References: https://ubuntu.com/security/notices/USN-7417-1, https://ubuntu.com/security/CVE-2016-1249, https://ubuntu.com/security/CVE-2016-1251, https://ubuntu.com/security/CVE-2017-10788, https://ubuntu.com/security/CVE-2017-10789
Affected packages
Package
Name: libdbd-mysql-perl
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
