DBD::mysql 4.039 released
Patrick Galbraith <[email protected]>
| Newsgroups | gmane.comp.lang.perl.modules.dbi.announce,gmane.comp.lang.perl.modules.dbi.general |
|---|---|
| Message-ID | <[email protected]> |
Dear Perl community, I’m pleased to announce the release of DBD::Mysql 4.039. This release contains a fix to a vulnerability that was found and now fixed per CVE-2016-1249. A description from the advisory reads: A vulnerability was discovered that can lead to an out-of-bounds read when using server side prepared statements with an unaligned number of placeholders in WHERE condition and output fields in SELECT expression. Versions known to be affected — 2.9004 and later (2005 and later) Versions known to be not affected — 2.9003 and earlier (before 2005) Version containing Fix — 4.039 and later (current) Thanks to Pali Rohár for discovering and fixing this vulnerability! The mirrors on CPAN should now be up to date and the release found at http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm <http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm> The source code available at https://github.com/perl5-dbi/DBD-mysql Regards, Patrick and Michiel
signature.asc
(application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJYLZR1AAoJEG2J7DMyUes4WGEP/Rt2b2I1tPScuushRk9xRGRq Tv2pZKABCrCZISu6AeWsqnM7ahh05KxJtZiQbIl3PCGelaCW2eFUs5BpLHtTUT+v BEOTlm8DZiK94SDSb4AtAial6LZ2VKifLqEEPYdpuJtKxy8NwIwRmsIBbpukXl9v yx1O3RGCXN2uCbzhgi8KFpHCpBZlxqLYTNyeZsfGNKn5mpsW/zPhD9gO+6Lxs+Db lrpbwySiwjKPw0ZaNaS56Nm0Er+Lh2HztfT1IBmdDlJkD4+yMw/pCCxvKZ4lVn6S tNbPLP2fT4ibzb0VC9b7N4X6ucEGPQZG2qVyugm3B+TxLUMcpVzzsj0pjTxOTAOE 7ds1mtvhY+iDNumkIElRePKxCzzbyJyFX7OrELY/G1eTzpPaZQIvOOfw/IyUmqzH SPEB51pW1BubM51MsQv2hJccVnvOtEDDGXa54En+yJ1X3sXK6S575EOOtIvvzx3M jGeTDaO2JwhjU9z4t/hi4JpiZH80aTCTLIV94KSkuWfYdcq+pc5z9Tbka/7k3O1V mZbNAyXnWFLiFtU9uk+4nQIHVpUfDxcDI34ntlDetYh1iLKd9IShk+HcA7ft/jLw Npr/uPlrX+M8iAGPTgWFvex0S+scKlDD6GANLTKqCM5wKx3EbTz5rB23GpN3qvaJ pbNU/fDDZLuFO8I7f2Ix =bW3q -----END PGP SIGNATURE-----