Описание
Security update for perl-DBI
This update for perl-DBI fixes the following issues:
Security issues fixed:
- CVE-2020-14392: Memory corruption in XS functions when Perl stack is reallocated (bsc#1176412).
- CVE-2020-14393: Fixed a buffer overflow on an overlong DBD class name (bsc#1176409).
Список пакетов
Container suse/rmt-mariadb:latest
perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-Azure
perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-EC2-HVM
perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-GCE
perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure
perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM
perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE
perl-DBI-1.642-3.3.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure
perl-DBI-1.642-3.3.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM
perl-DBI-1.642-3.3.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE
perl-DBI-1.642-3.3.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
perl-DBI-1.642-3.3.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
perl-DBI-1.642-3.3.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Server-4-3
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
perl-DBI-1.642-3.3.1
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
perl-DBI-1.642-3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP2
perl-DBI-1.642-3.3.1
Ссылки
- Link for SUSE-SU-2020:2646-1
- E-Mail link for SUSE-SU-2020:2646-1
- SUSE Security Ratings
- SUSE Bug 1176409
- SUSE Bug 1176412
- SUSE CVE CVE-2020-14392 page
- SUSE CVE CVE-2020-14393 page
Описание
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
Затронутые продукты
Container suse/rmt-mariadb:latest:perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-Azure:perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-EC2-HVM:perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-GCE:perl-DBI-1.642-3.3.1
Ссылки
- CVE-2020-14392
- SUSE Bug 1176412
Описание
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
Затронутые продукты
Container suse/rmt-mariadb:latest:perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-Azure:perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-EC2-HVM:perl-DBI-1.642-3.3.1
Image SLES15-SP2-Manager-4-1-Proxy-BYOS-GCE:perl-DBI-1.642-3.3.1
Ссылки
- CVE-2020-14393
- SUSE Bug 1176409