DBD::mysql 4.039 released
[email protected] (Patrick Galbraith) Thu, 17 Nov 2016 06:28:45 -0500
| Newsgroups | perl.dbi.users,perl.dbi.announce |
|---|---|
| Message-ID | <[email protected]> |
--Apple-Mail=_FF0CCFD6-BB2C-40DF-AE79-74C9524FA48F Content-Type: multipart/alternative; boundary="Apple-Mail=_48151E9E-26D6-4966-B9BC-C015767CB661" --Apple-Mail=_48151E9E-26D6-4966-B9BC-C015767CB661 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Dear Perl community, I=E2=80=99m pleased to announce the release of DBD::Mysql 4.039. This = release contains a fix to a vulnerability that was found and now fixed = per CVE-2016-1249. A description from the advisory reads: A vulnerability was discovered that can lead to an out-of-bounds read when using server side prepared statements with an unaligned number of placeholders in WHERE condition and output fields in SELECT expression. Versions known to be affected =E2=80=94 2.9004 and later (2005 and = later) Versions known to be not affected =E2=80=94 2.9003 and earlier (before = 2005) Version containing Fix =E2=80=94 4.039 and later (current) Thanks to Pali Roh=C3=A1r for discovering and fixing this vulnerability! The mirrors on CPAN should now be up to date and the release found at = http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm = <http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm> The source code available at https://github.com/perl5-dbi/DBD-mysql Regards, Patrick and Michiel --Apple-Mail=_48151E9E-26D6-4966-B9BC-C015767CB661 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html = charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" = class=3D"">Dear Perl community,<div class=3D""><br class=3D""></div><div = class=3D"">I=E2=80=99m pleased to announce the release of DBD::Mysql = 4.039. This release contains a fix to a vulnerability that was found and = now fixed per CVE-2016-1249. A description from the advisory = reads:</div><div class=3D""><br class=3D""></div><div class=3D"">A = vulnerability was discovered that can lead to an out-of-bounds = read</div><div class=3D"">when using server side prepared statements = with an unaligned number of<br class=3D"">placeholders in WHERE = condition and output fields in SELECT expression.<br class=3D""><br = class=3D"">Versions known to be affected =E2=80=94 2.9004 and later = (2005 and later)<br class=3D"">Versions known to be not affected =E2=80=94= 2.9003 and earlier (before 2005)<br class=3D"">Version containing Fix = =E2=80=94 4.039 and later (current)</div><div class=3D""><br = class=3D""></div><div class=3D"">Thanks to Pali Roh=C3=A1r for = discovering and fixing this vulnerability!</div><div class=3D""><br = class=3D""></div><div class=3D"">The mirrors on CPAN should now be up to = date and the release found at <a = href=3D"http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.pm"= = class=3D"">http://search.cpan.org/~capttofu/DBD-mysql-4.039/lib/DBD/mysql.= pm</a></div><div class=3D""><br class=3D""></div><div class=3D"">The = source code available at <a = href=3D"https://github.com/perl5-dbi/DBD-mysql" = class=3D"">https://github.com/perl5-dbi/DBD-mysql</a></div><div = class=3D""><br class=3D""></div><div class=3D"">Regards,<br class=3D""><br= class=3D"">Patrick and Michiel</div><div class=3D""><br = class=3D""></div><div class=3D""><br class=3D""></div></body></html>= --Apple-Mail=_48151E9E-26D6-4966-B9BC-C015767CB661-- --Apple-Mail=_FF0CCFD6-BB2C-40DF-AE79-74C9524FA48F Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP using GPGMail -----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJYLZR1AAoJEG2J7DMyUes4WGEP/Rt2b2I1tPScuushRk9xRGRq Tv2pZKABCrCZISu6AeWsqnM7ahh05KxJtZiQbIl3PCGelaCW2eFUs5BpLHtTUT+v BEOTlm8DZiK94SDSb4AtAial6LZ2VKifLqEEPYdpuJtKxy8NwIwRmsIBbpukXl9v yx1O3RGCXN2uCbzhgi8KFpHCpBZlxqLYTNyeZsfGNKn5mpsW/zPhD9gO+6Lxs+Db lrpbwySiwjKPw0ZaNaS56Nm0Er+Lh2HztfT1IBmdDlJkD4+yMw/pCCxvKZ4lVn6S tNbPLP2fT4ibzb0VC9b7N4X6ucEGPQZG2qVyugm3B+TxLUMcpVzzsj0pjTxOTAOE 7ds1mtvhY+iDNumkIElRePKxCzzbyJyFX7OrELY/G1eTzpPaZQIvOOfw/IyUmqzH SPEB51pW1BubM51MsQv2hJccVnvOtEDDGXa54En+yJ1X3sXK6S575EOOtIvvzx3M jGeTDaO2JwhjU9z4t/hi4JpiZH80aTCTLIV94KSkuWfYdcq+pc5z9Tbka/7k3O1V mZbNAyXnWFLiFtU9uk+4nQIHVpUfDxcDI34ntlDetYh1iLKd9IShk+HcA7ft/jLw Npr/uPlrX+M8iAGPTgWFvex0S+scKlDD6GANLTKqCM5wKx3EbTz5rB23GpN3qvaJ pbNU/fDDZLuFO8I7f2Ix =bW3q -----END PGP SIGNATURE----- --Apple-Mail=_FF0CCFD6-BB2C-40DF-AE79-74C9524FA48F--