Vulnerability Description
Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dbd-Mysql Project | Dbd-Mysql | <= 4.036 |
| Perl | Perl | All versions |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://blogs.perl.org/users/mike_b/2016/10/security-release---buffer-overflow-inThird Party AdvisoryVendor Advisory
- http://www.debian.org/security/2016/dsa-3684Third Party Advisory
- http://www.securityfocus.com/bid/93337Third Party AdvisoryVDB Entry
- https://github.com/perl5-dbi/DBD-mysql/commit/7c164a0c86cec6ee95df1d141e67b0e85dIssue TrackingPatch
- https://security.gentoo.org/glsa/201701-51PatchThird Party AdvisoryVDB Entry
- http://blogs.perl.org/users/mike_b/2016/10/security-release---buffer-overflow-inThird Party AdvisoryVendor Advisory
- http://www.debian.org/security/2016/dsa-3684Third Party Advisory
- http://www.securityfocus.com/bid/93337Third Party AdvisoryVDB Entry
- https://github.com/perl5-dbi/DBD-mysql/commit/7c164a0c86cec6ee95df1d141e67b0e85dIssue TrackingPatch
- https://security.gentoo.org/glsa/201701-51PatchThird Party AdvisoryVDB Entry
FAQ
What is CVE-2016-1246?
CVE-2016-1246 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.
How severe is CVE-2016-1246?
CVE-2016-1246 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1246?
Check the references section above for vendor advisories and patch information. Affected products include: Dbd-Mysql Project Dbd-Mysql, Perl Perl, Debian Debian Linux.