Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2827-1

Опубликовано: 02 окт. 2020
Источник: suse-cvrf

Описание

Security update for perl-DBI

This update for perl-DBI fixes the following issues:

  • CVE-2019-20919: Fixed a NULL profile dereference in dbi_profile (bsc#1176764).

Список пакетов

Image SLES15-SP1-Manager-4-0-Azure-BYOS-Proxy
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Proxy
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Server
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-GCE-BYOS-Proxy
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-GCE-BYOS-Server
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Module for Basesystem 15 SP1
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Server 15-LTSS
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Server for SAP Applications 15
perl-DBI-1.639-3.11.1

Описание

An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.


Затронутые продукты
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Proxy:perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server:perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Proxy:perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Server:perl-DBI-1.639-3.11.1

Ссылки