Bug#866821: libdbd-mysql-perl: CVE-2017-10789

2017-08-30 Thread Antoine Beaupre
On Mon, Aug 28, 2017 at 02:53:12PM +0200, Guido Günther wrote: > While a patch for this was upstream in 4.042 (around > b6be72f321e920419bdc5c86998d9b9cb26c6791) upstream reverted _all_ > changes of back to 4.041. That's right, like #866818... I've backported the patch to wheezy, but this is

Bug#866821: libdbd-mysql-perl: CVE-2017-10789

2017-08-28 Thread Guido Günther
Hi, On Sun, Jul 02, 2017 at 09:26:07AM +0200, Salvatore Bonaccorso wrote: > Source: libdbd-mysql-perl > Version: 4.028-2 > Severity: important > Tags: security upstream > > Hi, > > the following vulnerability was published for libdbd-mysql-perl. > > CVE-2017-10789[0]: > | The DBD::mysql module

Bug#866821: libdbd-mysql-perl: CVE-2017-10789

2017-07-02 Thread Salvatore Bonaccorso
Source: libdbd-mysql-perl Version: 4.028-2 Severity: important Tags: security upstream Hi, the following vulnerability was published for libdbd-mysql-perl. CVE-2017-10789[0]: | The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 | setting to mean that SSL is optional (even though