DBD::mysql 4.039 released

Patrick Galbraith <[email protected]>
Newsgroups gmane.comp.lang.perl.modules.dbi.announce,gmane.comp.lang.perl.modules.dbi.general
Message-ID <[email protected]>
Dear Perl community,

I’m pleased to announce the release of DBD::Mysql 4.039. This release contains a fix to a vulnerability that was found and now fixed per CVE-2016-1249. A description from the advisory reads:

A vulnerability was discovered that can lead to an out-of-bounds read
when using server side prepared statements with an unaligned number of
placeholders in WHERE condition and output fields in SELECT expression.

Versions known to be affected — 2.9004 and later (2005 and later)
Versions known to be not affected — 2.9003 and earlier (before 2005)
Version containing Fix — 4.039 and later (current)

Thanks to Pali Rohár for discovering and fixing this vulnerability!

The mirrors on CPAN should now be up to date and the release found at http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm <http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm>

The source code available at https://github.com/perl5-dbi/DBD-mysql

Regards,

Patrick and Michiel
signature.asc (application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJYLZR1AAoJEG2J7DMyUes4WGEP/Rt2b2I1tPScuushRk9xRGRq
Tv2pZKABCrCZISu6AeWsqnM7ahh05KxJtZiQbIl3PCGelaCW2eFUs5BpLHtTUT+v
BEOTlm8DZiK94SDSb4AtAial6LZ2VKifLqEEPYdpuJtKxy8NwIwRmsIBbpukXl9v
yx1O3RGCXN2uCbzhgi8KFpHCpBZlxqLYTNyeZsfGNKn5mpsW/zPhD9gO+6Lxs+Db
lrpbwySiwjKPw0ZaNaS56Nm0Er+Lh2HztfT1IBmdDlJkD4+yMw/pCCxvKZ4lVn6S
tNbPLP2fT4ibzb0VC9b7N4X6ucEGPQZG2qVyugm3B+TxLUMcpVzzsj0pjTxOTAOE
7ds1mtvhY+iDNumkIElRePKxCzzbyJyFX7OrELY/G1eTzpPaZQIvOOfw/IyUmqzH
SPEB51pW1BubM51MsQv2hJccVnvOtEDDGXa54En+yJ1X3sXK6S575EOOtIvvzx3M
jGeTDaO2JwhjU9z4t/hi4JpiZH80aTCTLIV94KSkuWfYdcq+pc5z9Tbka/7k3O1V
mZbNAyXnWFLiFtU9uk+4nQIHVpUfDxcDI34ntlDetYh1iLKd9IShk+HcA7ft/jLw
Npr/uPlrX+M8iAGPTgWFvex0S+scKlDD6GANLTKqCM5wKx3EbTz5rB23GpN3qvaJ
pbNU/fDDZLuFO8I7f2Ix
=bW3q
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.