CVE-2015-8949
published 2016-08-19CVE-2015-8949: Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to…
PriorityP341critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.49%
90.5th percentile
Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dbd-mysql_project | dbd-mysql | — | — |
| debian | debian_linux | — | — |
| debian | libdbd-mysql-perl | < libdbd-mysql-perl 4.035-1 (bookworm) | libdbd-mysql-perl 4.035-1 (bookworm) |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-48mj-69cx-pcqg: Use-after-free vulnerability in the my_login function in DBD::mysql before 4
ghsa_unreviewed·2022-05-17
CVE-2015-8949 [CRITICAL] CWE-416 GHSA-48mj-69cx-pcqg: Use-after-free vulnerability in the my_login function in DBD::mysql before 4
Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login.
OSV
libdbd-mysql-perl vulnerabilities
osv·2016-10-13·CVSS 9.8
CVE-2014-9906 [CRITICAL] libdbd-mysql-perl vulnerabilities
libdbd-mysql-perl vulnerabilities
It was discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2014-9906)
Hanno Böck discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2015-8949)
Pali Rohár discovered that DBD::mysql incorrectly handled certain user
supplied data. A remote attacker could use this issue to cause DBD::mysql
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-1246)
OSV
CVE-2015-8949: Use-after-free vulnerability in the my_login function in DBD::mysql before 4
osv·2016-08-19·CVSS 9.8
CVE-2015-8949 [CRITICAL] CVE-2015-8949: Use-after-free vulnerability in the my_login function in DBD::mysql before 4
Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login.
Ubuntu
DBD::mysql vulnerabilities
vendor_ubuntu·2016-10-13·CVSS 9.8
CVE-2014-9906 [CRITICAL] DBD::mysql vulnerabilities
Title: DBD::mysql vulnerabilities
Summary: DBD::mysql could be made to crash or run programs if it received specially
crafted input.
It was discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2014-9906)
Hanno Böck discovered that DBD::mysql incorrectly handled certain memory
operations. A remote attacker could use this issue to cause DBD::mysql to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2015-8949)
Pali Rohár discovered that DBD::mysql incorrectly handled certain user
supplied data. A remote attacker could use this issue to cause DBD::mysql
to crash, resulting in a denial of service
Red Hat
perl-DBD-MySQL: Use after free when my_login fails
vendor_redhat·2015-11-14·CVSS 9.8
CVE-2015-8949 [CRITICAL] CWE-416 perl-DBD-MySQL: Use after free when my_login fails
perl-DBD-MySQL: Use after free when my_login fails
Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login.
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 5) - Not affected
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 6) - Not affected
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 7) - Not affected
Package: perl516-perl-DBD-MySQL (Red Hat Software Collections) - Not affected
Package: rh-perl520-perl-DBD-MySQL (Red Hat Software Collections) - Will not fix
Debian
CVE-2015-8949: libdbd-mysql-perl - Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033...
vendor_debian·2015·CVSS 9.8
CVE-2015-8949 [CRITICAL] CVE-2015-8949: libdbd-mysql-perl - Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033...
Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login.
Scope: local
bookworm: resolved (fixed in 4.035-1)
bullseye: resolved (fixed in 4.035-1)
forky: resolved (fixed in 4.035-1)
sid: resolved (fixed in 4.035-1)
trixie: resolved (fixed in 4.035-1)
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2016/dsa-3635http://www.openwall.com/lists/oss-security/2016/07/25/13http://www.openwall.com/lists/oss-security/2016/07/27/1http://www.securityfocus.com/bid/92118https://blog.fuzzing-project.org/50-Use-after-free-in-my_login-function-of-DBDmysql-Perl-module.htmlhttps://github.com/perl5-dbi/DBD-mysql/blob/4.033_01/Changeshttps://github.com/perl5-dbi/DBD-mysql/commit/cf0aa7751f6ef8445e9310a64b14dc81460ca156https://github.com/perl5-dbi/DBD-mysql/pull/45https://security.gentoo.org/glsa/201701-51http://www.debian.org/security/2016/dsa-3635http://www.openwall.com/lists/oss-security/2016/07/25/13http://www.openwall.com/lists/oss-security/2016/07/27/1http://www.securityfocus.com/bid/92118https://blog.fuzzing-project.org/50-Use-after-free-in-my_login-function-of-DBDmysql-Perl-module.htmlhttps://github.com/perl5-dbi/DBD-mysql/blob/4.033_01/Changeshttps://github.com/perl5-dbi/DBD-mysql/commit/cf0aa7751f6ef8445e9310a64b14dc81460ca156https://github.com/perl5-dbi/DBD-mysql/pull/45https://security.gentoo.org/glsa/201701-51
2016-08-19
Published