CVE-2014-9906
published 2016-08-19CVE-2014-9906: Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via…
PriorityP346critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.03%
92.6th percentile
Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dbd-mysql_project | dbd-mysql | <= 4.028 | — |
| debian | debian_linux | — | — |
| debian | libdbd-mysql-perl | < libdbd-mysql-perl 4.033-1 (bookworm) | libdbd-mysql-perl 4.033-1 (bookworm) |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-676f-4267-c5c3: Use-after-free vulnerability in DBD::mysql before 4
ghsa_unreviewed·2022-05-17
CVE-2014-9906 [CRITICAL] CWE-416 GHSA-676f-4267-c5c3: Use-after-free vulnerability in DBD::mysql before 4
Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection.
OSV
libdbd-mysql-perl vulnerabilities
osv·2016-10-13·CVSS 9.8
CVE-2014-9906 [CRITICAL] libdbd-mysql-perl vulnerabilities
libdbd-mysql-perl vulnerabilities
It was discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2014-9906)
Hanno Böck discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2015-8949)
Pali Rohár discovered that DBD::mysql incorrectly handled certain user
supplied data. A remote attacker could use this issue to cause DBD::mysql
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-1246)
OSV
CVE-2014-9906: Use-after-free vulnerability in DBD::mysql before 4
osv·2016-08-19·CVSS 9.8
CVE-2014-9906 [CRITICAL] CVE-2014-9906: Use-after-free vulnerability in DBD::mysql before 4
Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection.
Ubuntu
DBD::mysql vulnerabilities
vendor_ubuntu·2016-10-13·CVSS 9.8
CVE-2014-9906 [CRITICAL] DBD::mysql vulnerabilities
Title: DBD::mysql vulnerabilities
Summary: DBD::mysql could be made to crash or run programs if it received specially
crafted input.
It was discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2014-9906)
Hanno Böck discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2015-8949)
Pali Rohár discovered that DBD::mysql incorrectly handled certain user
supplied data. A remote attacker could use this issue to cause DBD::mysql
to crash, resulting in a denial of service
Red Hat
perl-DBD-MySQL: Use after free in mysql_dr_error
vendor_redhat·2014-08-01·CVSS 9.8
CVE-2014-9906 [CRITICAL] CWE-416 perl-DBD-MySQL: Use after free in mysql_dr_error
perl-DBD-MySQL: Use after free in mysql_dr_error
Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection.
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 5) - Not affected
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 6) - Not affected
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 7) - Not affected
Package: perl516-perl-DBD-MySQL (Red Hat Software Collections) - Not affected
Package: rh-perl520-perl-DBD-MySQL (Red Hat Software Collections) - Not affected
Debian
CVE-2014-9906: libdbd-mysql-perl - Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to caus...
vendor_debian·2014·CVSS 9.8
CVE-2014-9906 [CRITICAL] CVE-2014-9906: libdbd-mysql-perl - Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to caus...
Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection.
Scope: local
bookworm: resolved (fixed in 4.033-1)
bullseye: resolved (fixed in 4.033-1)
forky: resolved (fixed in 4.033-1)
sid: resolved (fixed in 4.033-1)
trixie: resolved (fixed in 4.033-1)
No detection rules found.
No public exploits indexed.
http://cpansearch.perl.org/src/CAPTTOFU/DBD-mysql-4.029/ChangeLoghttp://www.debian.org/security/2016/dsa-3635http://www.openwall.com/lists/oss-security/2016/07/27/5http://www.openwall.com/lists/oss-security/2016/07/27/6http://www.securityfocus.com/bid/92149https://github.com/perl5-dbi/DBD-mysql/commit/a56ae87a4c1c1fead7d09c3653905841ccccf1cchttps://rt.cpan.org/Public/Bug/Display.html?id=97625http://cpansearch.perl.org/src/CAPTTOFU/DBD-mysql-4.029/ChangeLoghttp://www.debian.org/security/2016/dsa-3635http://www.openwall.com/lists/oss-security/2016/07/27/5http://www.openwall.com/lists/oss-security/2016/07/27/6http://www.securityfocus.com/bid/92149https://github.com/perl5-dbi/DBD-mysql/commit/a56ae87a4c1c1fead7d09c3653905841ccccf1cchttps://rt.cpan.org/Public/Bug/Display.html?id=97625
2016-08-19
Published