Vulnerability Name: | CVE-2015-8949 (CCN-116289) | ||||||||||||||||||||||||
Assigned: | 2016-07-25 | ||||||||||||||||||||||||
Published: | 2016-07-25 | ||||||||||||||||||||||||
Updated: | 2017-07-01 | ||||||||||||||||||||||||
Summary: | Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login. | ||||||||||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-416 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8949 Source: DEBIAN Type: Third Party Advisory DSA-3635 Source: CCN Type: oss-sec Mailing List, Mon, 25 Jul 2016 13:34:17 -0400 Use after free in my_login() function of DBD::mysql (Perl module) Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160725 Use after free in my_login() function of DBD::mysql (Perl module) Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160726 Re: Use after free in my_login() function of DBD::mysql (Perl module) Source: BID Type: UNKNOWN 92118 Source: CCN Type: BID-92118 DBD::mysql 'my_login()' Function Use After Free Remote Code Execution Vulnerability Source: MISC Type: Third Party Advisory https://blog.fuzzing-project.org/50-Use-after-free-in-my_login-function-of-DBDmysql-Perl-module.html Source: XF Type: UNKNOWN perl5dbi-dbdmysql-cve20158949-code-exec(116289) Source: CCN Type: DBD-mysql GIT Repository GitHub - perl5-dbi/DBD-mysql: MySQL driver for the Perl5 Database Interface (DBI) Source: CONFIRM Type: Release Notes https://github.com/perl5-dbi/DBD-mysql/blob/4.033_01/Changes Source: CONFIRM Type: Issue Tracking, Patch https://github.com/perl5-dbi/DBD-mysql/commit/cf0aa7751f6ef8445e9310a64b14dc81460ca156 Source: CONFIRM Type: Issue Tracking, Patch https://github.com/perl5-dbi/DBD-mysql/pull/45 Source: GENTOO Type: UNKNOWN GLSA-201701-51 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8949 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |