Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2661-1

Опубликовано: 16 сент. 2020
Источник: suse-cvrf

Описание

Security update for perl-DBI

This update for perl-DBI fixes the following issues:

Security issues fixed:

  • CVE-2020-14392: Memory corruption in XS functions when Perl stack is reallocated (bsc#1176412).
  • CVE-2020-14393: Fixed a buffer overflow on an overlong DBD class name (bsc#1176409).

Список пакетов

HPE Helion OpenStack 8
perl-DBI-1.628-5.3.1
SUSE Enterprise Storage 5
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP2-BCL
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP2-LTSS
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP3-BCL
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP3-LTSS
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP4-LTSS
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP5
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
perl-DBI-1.628-5.3.1
SUSE OpenStack Cloud 7
perl-DBI-1.628-5.3.1
SUSE OpenStack Cloud 8
perl-DBI-1.628-5.3.1
SUSE OpenStack Cloud 9
perl-DBI-1.628-5.3.1
SUSE OpenStack Cloud Crowbar 8
perl-DBI-1.628-5.3.1
SUSE OpenStack Cloud Crowbar 9
perl-DBI-1.628-5.3.1

Описание

An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.


Затронутые продукты
HPE Helion OpenStack 8:perl-DBI-1.628-5.3.1
SUSE Enterprise Storage 5:perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP2-BCL:perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP2-LTSS:perl-DBI-1.628-5.3.1

Ссылки

Описание

A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.


Затронутые продукты
HPE Helion OpenStack 8:perl-DBI-1.628-5.3.1
SUSE Enterprise Storage 5:perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP2-BCL:perl-DBI-1.628-5.3.1
SUSE Linux Enterprise Server 12 SP2-LTSS:perl-DBI-1.628-5.3.1

Ссылки