Bug#866818: libdbd-mysql-perl: CVE-2017-10788

2017-08-30 Thread Guido Günther
Hi, On Wed, Aug 30, 2017 at 12:51:24PM -0400, Antoine Beaupre wrote: > On Mon, Aug 28, 2017 at 02:56:36PM +0200, Guido Günther wrote: > > I've pinged upstream again why the patch is still pending: > > > > https://github.com/perl5-dbi/DBD-mysql/issues/120#issuecomment-325342844 > > After

Bug#866818: libdbd-mysql-perl: CVE-2017-10788

2017-08-30 Thread Antoine Beaupre
On Mon, Aug 28, 2017 at 02:56:36PM +0200, Guido Günther wrote: > I've pinged upstream again why the patch is still pending: > > https://github.com/perl5-dbi/DBD-mysql/issues/120#issuecomment-325342844 After reviewing the original advisory and the suggested patch, I have opened that PR in:

Bug#866818: libdbd-mysql-perl: CVE-2017-10788

2017-08-28 Thread Guido Günther
Hi, On Sun, Jul 02, 2017 at 09:15:39AM +0200, Salvatore Bonaccorso wrote: > Source: libdbd-mysql-perl > Version: 4.028-2 > Severity: important > Tags: security upstream > > Hi, > > the following vulnerability was published for libdbd-mysql-perl. > > CVE-2017-10788[0]: > | The DBD::mysql module

Bug#866818: libdbd-mysql-perl: CVE-2017-10788

2017-07-02 Thread Salvatore Bonaccorso
Source: libdbd-mysql-perl Version: 4.028-2 Severity: important Tags: security upstream Hi, the following vulnerability was published for libdbd-mysql-perl. CVE-2017-10788[0]: | The DBD::mysql module through 4.043 for Perl allows remote attackers to | cause a denial of service (use-after-free