Описание
Security update for perl-DBI
This update for perl-DBI fixes the following issues:
- CVE-2019-20919: Fixed a NULL profile dereference in dbi_profile (bsc#1176764).
Список пакетов
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Proxy
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Proxy
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Server
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-GCE-BYOS-Proxy
perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-GCE-BYOS-Server
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Module for Basesystem 15 SP1
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Server 15-LTSS
perl-DBI-1.639-3.11.1
SUSE Linux Enterprise Server for SAP Applications 15
perl-DBI-1.639-3.11.1
Ссылки
- Link for SUSE-SU-2020:2827-1
- E-Mail link for SUSE-SU-2020:2827-1
- SUSE Security Ratings
- SUSE Bug 1176764
- SUSE CVE CVE-2019-20919 page
Описание
An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.
Затронутые продукты
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Proxy:perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server:perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Proxy:perl-DBI-1.639-3.11.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Server:perl-DBI-1.639-3.11.1
Ссылки
- CVE-2019-20919
- SUSE Bug 1176764