DBD::mysql 4.039 released

[email protected] (Patrick Galbraith) Thu, 17 Nov 2016 06:28:45 -0500
Newsgroups perl.dbi.users,perl.dbi.announce
Message-ID <[email protected]>
--Apple-Mail=_FF0CCFD6-BB2C-40DF-AE79-74C9524FA48F
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_48151E9E-26D6-4966-B9BC-C015767CB661"


--Apple-Mail=_48151E9E-26D6-4966-B9BC-C015767CB661
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Dear Perl community,

I=E2=80=99m pleased to announce the release of DBD::Mysql 4.039. This =
release contains a fix to a vulnerability that was found and now fixed =
per CVE-2016-1249. A description from the advisory reads:

A vulnerability was discovered that can lead to an out-of-bounds read
when using server side prepared statements with an unaligned number of
placeholders in WHERE condition and output fields in SELECT expression.

Versions known to be affected =E2=80=94 2.9004 and later (2005 and =
later)
Versions known to be not affected =E2=80=94 2.9003 and earlier (before =
2005)
Version containing Fix =E2=80=94 4.039 and later (current)

Thanks to Pali Roh=C3=A1r for discovering and fixing this vulnerability!

The mirrors on CPAN should now be up to date and the release found at =
http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm =
<http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm>

The source code available at https://github.com/perl5-dbi/DBD-mysql

Regards,

Patrick and Michiel



--Apple-Mail=_48151E9E-26D6-4966-B9BC-C015767CB661
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">Dear Perl community,<div class=3D""><br class=3D""></div><div =
class=3D"">I=E2=80=99m pleased to announce the release of DBD::Mysql =
4.039. This release contains a fix to a vulnerability that was found and =
now fixed per CVE-2016-1249. A description from the advisory =
reads:</div><div class=3D""><br class=3D""></div><div class=3D"">A =
vulnerability was discovered that can lead to an out-of-bounds =
read</div><div class=3D"">when using server side prepared statements =
with an unaligned number of<br class=3D"">placeholders in WHERE =
condition and output fields in SELECT expression.<br class=3D""><br =
class=3D"">Versions known to be affected =E2=80=94 2.9004 and later =
(2005 and later)<br class=3D"">Versions known to be not affected =E2=80=94=
 2.9003 and earlier (before 2005)<br class=3D"">Version containing Fix =
=E2=80=94 4.039 and later (current)</div><div class=3D""><br =
class=3D""></div><div class=3D"">Thanks to Pali Roh=C3=A1r for =
discovering and fixing this vulnerability!</div><div class=3D""><br =
class=3D""></div><div class=3D"">The mirrors on CPAN should now be up to =
date and the release found at&nbsp;<a =
href=3D"http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm"=
 =
class=3D"">http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.=
pm</a></div><div class=3D""><br class=3D""></div><div class=3D"">The =
source code available at&nbsp;<a =
href=3D"https://github.com/perl5-dbi/DBD-mysql" =
class=3D"">https://github.com/perl5-dbi/DBD-mysql</a></div><div =
class=3D""><br class=3D""></div><div class=3D"">Regards,<br class=3D""><br=
 class=3D"">Patrick and Michiel</div><div class=3D""><br =
class=3D""></div><div class=3D""><br class=3D""></div></body></html>=

--Apple-Mail=_48151E9E-26D6-4966-B9BC-C015767CB661--

--Apple-Mail=_FF0CCFD6-BB2C-40DF-AE79-74C9524FA48F
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJYLZR1AAoJEG2J7DMyUes4WGEP/Rt2b2I1tPScuushRk9xRGRq
Tv2pZKABCrCZISu6AeWsqnM7ahh05KxJtZiQbIl3PCGelaCW2eFUs5BpLHtTUT+v
BEOTlm8DZiK94SDSb4AtAial6LZ2VKifLqEEPYdpuJtKxy8NwIwRmsIBbpukXl9v
yx1O3RGCXN2uCbzhgi8KFpHCpBZlxqLYTNyeZsfGNKn5mpsW/zPhD9gO+6Lxs+Db
lrpbwySiwjKPw0ZaNaS56Nm0Er+Lh2HztfT1IBmdDlJkD4+yMw/pCCxvKZ4lVn6S
tNbPLP2fT4ibzb0VC9b7N4X6ucEGPQZG2qVyugm3B+TxLUMcpVzzsj0pjTxOTAOE
7ds1mtvhY+iDNumkIElRePKxCzzbyJyFX7OrELY/G1eTzpPaZQIvOOfw/IyUmqzH
SPEB51pW1BubM51MsQv2hJccVnvOtEDDGXa54En+yJ1X3sXK6S575EOOtIvvzx3M
jGeTDaO2JwhjU9z4t/hi4JpiZH80aTCTLIV94KSkuWfYdcq+pc5z9Tbka/7k3O1V
mZbNAyXnWFLiFtU9uk+4nQIHVpUfDxcDI34ntlDetYh1iLKd9IShk+HcA7ft/jLw
Npr/uPlrX+M8iAGPTgWFvex0S+scKlDD6GANLTKqCM5wKx3EbTz5rB23GpN3qvaJ
pbNU/fDDZLuFO8I7f2Ix
=bW3q
-----END PGP SIGNATURE-----

--Apple-Mail=_FF0CCFD6-BB2C-40DF-AE79-74C9524FA48F--