The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
CVSS Details
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libdbd-mysql-perl | Jul 30, 2024 | Feb 17, 2017 |
| Gentoo Linux | — | Upgrade dev-perl/DBD-mysql. | Oct 30, 2017 | Feb 16, 2017 |
| Huawei Euleros 2_0_sp2 | — | — | Feb 22, 2021 | Feb 17, 2017 |
| Huawei Euleros 2_0_sp3 | — | — | Apr 30, 2021 | Feb 17, 2017 |
| Huawei Euleros 2_0_sp5 | — | — | Feb 3, 2021 | Feb 17, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Feb 16, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 15, 2016 |
| Suse | — | Upgrade perl-DBD-mysql | Jan 12, 2017 | Jan 12, 2017 |
| Ubuntu | — | Upgrade libdbd-mysql-perl (Ubuntu Pro) | Mar 22, 2023 | Feb 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub