Boletines de Vulnerabilidades

DSA-3635 libdbd-mysql-perl - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

Two use-after-free vulnerabilities were discovered in DBD::mysql, a PerlDBI driver for the MySQL database server. A remote attacker can takeadvantage of these flaws to cause a denial-of-service against anapplication using DBD::mysql (application crash), or potentially toexecute arbitrary code with the privileges of the user running theapplication.

More info:

https://www.debian.org/security/2016/dsa-3635

Identificadores estándar

Propiedad Valor
CVE CVE-2014-9906 ,CVE-2015-8949 and DSA-3635.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2016-07-30

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT