CVE-2016-1249
published 2017-02-17CVE-2016-1249: The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds…
PriorityP424medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
2.43%
82.5th percentile
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dbd-mysql_project | dbd-mysql | <= 4.038_01 | — |
| debian | libdbd-mysql-perl | < libdbd-mysql-perl 4.039-1 (bookworm) | libdbd-mysql-perl 4.039-1 (bookworm) |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libdbd-mysql-perl vulnerabilities
osv·2025-04-07·CVSS 5.9
CVE-2016-1249 [MEDIUM] libdbd-mysql-perl vulnerabilities
libdbd-mysql-perl vulnerabilities
It was discovered that libdbd-mysql-perl did not correctly handle certain
SQL queries. An attacker could possibly use this issue to cause a denial
of service. (CVE-2016-1249)
It was discovered that libdbd-mysql-perl did not correctly handle certain
memory operations, which could lead to a use-after-free vulnerability. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2016-1251, CVE-2017-10788)
It was discovered that libdbd-mysql-perl did not properly enforce SSL
connections depending on the mysql_ssl setting. A machine-in-the-middle
attacker could possibly use this issue to spoof servers. (CVE-2017-10789)
GHSA
GHSA-v93g-vffx-whwx: The DBD::mysql module before 4
ghsa_unreviewed·2022-05-13
CVE-2016-1249 [MEDIUM] CWE-125 GHSA-v93g-vffx-whwx: The DBD::mysql module before 4
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
OSV
libdbd-mysql-perl vulnerabilities
osv·2022-04-01·CVSS 5.9
CVE-2016-1249 [MEDIUM] libdbd-mysql-perl vulnerabilities
libdbd-mysql-perl vulnerabilities
It was discovered that the DBD::mysql module, when configured with server-side
prepared statement support, was susceptible to operations that would result in
improper memory access. An attacker could possibly use this issue to cause
DBD::mysql to crash, resulting in a denial of service.
(CVE-2016-1249, CVE-2016-1251)
It was discovered that the DBD::mysql module was susceptible to an operation
that would result in improper memory access, introduced through incorrect
documentation and code examples. An attacker could possibly use this issue to
cause DBD::mysql to crash or potentially cause other, unspecified, impact.
(CVE-2017-10788)
It was discovered that the DBD::mysql module processed SSL/TLS settings in a
way that did not fully correlate with the resp
OSV
CVE-2016-1249: The DBD::mysql module before 4
osv·2017-02-17·CVSS 5.9
CVE-2016-1249 [MEDIUM] CVE-2016-1249: The DBD::mysql module before 4
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
Ubuntu
libdbd-mysql-perl vulnerabilities
vendor_ubuntu·2025-04-07·CVSS 5.9
CVE-2016-1251 [MEDIUM] libdbd-mysql-perl vulnerabilities
Title: libdbd-mysql-perl vulnerabilities
Summary: Several security issues were fixed in libdbd-mysql-perl.
It was discovered that libdbd-mysql-perl did not correctly handle certain
SQL queries. An attacker could possibly use this issue to cause a denial
of service. (CVE-2016-1249)
It was discovered that libdbd-mysql-perl did not correctly handle certain
memory operations, which could lead to a use-after-free vulnerability. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2016-1251, CVE-2017-10788)
It was discovered that libdbd-mysql-perl did not properly enforce SSL
connections depending on the mysql_ssl setting. A machine-in-the-middle
attacker could possibly use this issue to spoof servers. (CVE-2017-10789)
Instructions: In
Ubuntu
DBD::mysql vulnerabilities
vendor_ubuntu·2022-04-01·CVSS 5.9
CVE-2016-1249 [MEDIUM] DBD::mysql vulnerabilities
Title: DBD::mysql vulnerabilities
Summary: Several security issues were fixed in DBD::mysql.
It was discovered that the DBD::mysql module, when configured with server-side
prepared statement support, was susceptible to operations that would result in
improper memory access. An attacker could possibly use this issue to cause
DBD::mysql to crash, resulting in a denial of service.
(CVE-2016-1249, CVE-2016-1251)
It was discovered that the DBD::mysql module was susceptible to an operation
that would result in improper memory access, introduced through incorrect
documentation and code examples. An attacker could possibly use this issue to
cause DBD::mysql to crash or potentially cause other, unspecified, impact.
(CVE-2017-10788)
It was discovered that the DBD::mysql module processed SSL/TLS
Red Hat
perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support
vendor_redhat·2016-11-15·CVSS 5.9
CVE-2016-1249 [MEDIUM] CWE-125 perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support
perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 5) - Will not fix
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 6) - Will not fix
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 7) - Will not fix
Package: rh-perl520-perl-DBD-MySQL (Red Hat Software Collections) - Will not fix
Package: rh-perl524-perl-DBD-MySQL (Red Hat Software Collections) - Will not fix
Debian
CVE-2016-1249: libdbd-mysql-perl - The DBD::mysql module before 4.039 for Perl, when using server-side prepared sta...
vendor_debian·2016·CVSS 5.9
CVE-2016-1249 [MEDIUM] CVE-2016-1249: libdbd-mysql-perl - The DBD::mysql module before 4.039 for Perl, when using server-side prepared sta...
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
Scope: local
bookworm: resolved (fixed in 4.039-1)
bullseye: resolved (fixed in 4.039-1)
forky: resolved (fixed in 4.039-1)
sid: resolved (fixed in 4.039-1)
trixie: resolved (fixed in 4.039-1)
No detection rules found.
Bugzilla
CVE-2016-1249 perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support [fedora-all]
bugzilla·2016-11-16·CVSS 5.9
CVE-2016-1249 [MEDIUM] CVE-2016-1249 perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support [fedora-all]
CVE-2016-1249 perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2016-1249 perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support
bugzilla·2016-11-16·CVSS 5.9
CVE-2016-1249 [MEDIUM] CVE-2016-1249 perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support
CVE-2016-1249 perl-DBD-MySQL: Out-of-bounds read when using server-side prepared statement support
A vulnerability was discovered in perl-DBD-MySQL that can lead to an out-of-bounds read when using server side prepared statements with an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
This problem is only exposed when the user uses server-side prepared statement support, which is NOT default behavior and was turned off back for all drivers per MySQL AB decision in 2006 due to issues with server-side prepared statements in the server. The behavior of the driver is normally emulated.
References:
http://seclists.org/oss-sec/2016/q4/433
Upstream patch:
https://github.com/perl5-dbi/DBD-mysql/commit/793b72b1a0baa5070adacaac0e12fd995a6fbabe
Disc
http://cpansearch.perl.org/src/CAPTTOFU/DBD-mysql-4.039/Changeshttp://www.openwall.com/lists/oss-security/2016/11/16/1http://www.securityfocus.com/bid/94350https://github.com/perl5-dbi/DBD-mysql/commit/793b72b1a0baa5070adacaac0e12fd995a6fbabehttps://security.gentoo.org/glsa/201701-51http://cpansearch.perl.org/src/CAPTTOFU/DBD-mysql-4.039/Changeshttp://www.openwall.com/lists/oss-security/2016/11/16/1http://www.securityfocus.com/bid/94350https://github.com/perl5-dbi/DBD-mysql/commit/793b72b1a0baa5070adacaac0e12fd995a6fbabehttps://security.gentoo.org/glsa/201701-51
2017-02-17
Published