Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21029-1

Опубликовано: 22 июн. 2026
Источник: suse-cvrf

Описание

Security update for perl-DBI

This update for perl-DBI fixes the following issues

  • CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer (bsc#1267957).
  • CVE-2026-10879: SQL statements with more than 9 binders can cause an heap overflow (bsc#1267849).

Список пакетов

openSUSE Leap 16.0
perl-DBI-1.647.0-160000.3.1

Описание

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.


Затронутые продукты
openSUSE Leap 16.0:perl-DBI-1.647.0-160000.3.1

Ссылки

Описание

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow.


Затронутые продукты
openSUSE Leap 16.0:perl-DBI-1.647.0-160000.3.1

Ссылки