vulnerability

Ubuntu: (Multiple Advisories) (CVE-2016-1251): DBD::mysql vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Nov 29, 2016
Added
Mar 22, 2023
Modified
Apr 14, 2025

Description

It was discovered that the DBD::mysql module, when configured with server-side
prepared statement support, was susceptible to operations that would result in
improper memory access. An attacker could possibly use this issue to cause
DBD::mysql to crash, resulting in a denial of service.
(CVE-2016-1249, CVE-2016-1251)

It was discovered that the DBD::mysql module was susceptible to an operation
that would result in improper memory access, introduced through incorrect
documentation and code examples. An attacker could possibly use this issue to
cause DBD::mysql to crash or potentially cause other, unspecified, impact.
(CVE-2017-10788)

It was discovered that the DBD::mysql module processed SSL/TLS settings in a
way that did not fully correlate with the respective documentation for each
setting. An attacker could possibly use this to perform a cleartext-downgrade
attack. (CVE-2017-10789)

Solution

ubuntu-pro-upgrade-libdbd-mysql-perl
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.