There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libdbd-mysql-perl | Jul 30, 2024 | Nov 29, 2016 |
| Gentoo Linux | — | Upgrade dev-perl/DBD-mysql. | Oct 30, 2017 | Nov 29, 2016 |
| Huawei Euleros 2_0_sp2 | — | — | Nov 3, 2020 | Nov 29, 2016 |
| Huawei Euleros 2_0_sp3 | — | — | Sep 28, 2020 | Nov 29, 2016 |
| Huawei Euleros 2_0_sp5 | — | — | Dec 16, 2020 | Nov 29, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Nov 29, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 18, 2016 |
| Suse | — | Upgrade perl-DBD-mysql | Dec 12, 2016 | Nov 29, 2016 |
| Ubuntu | — | Upgrade libdbd-mysql-perl (Ubuntu Pro) | Mar 22, 2023 | Nov 29, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub