Описание
Security update for perl-DBI
This update for perl-DBI fixes the following issues
- CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer (bsc#1267957).
- CVE-2026-10879: SQL statements with more than 9 binders can cause an heap overflow (bsc#1267849).
Список пакетов
openSUSE Leap 16.0
perl-DBI-1.647.0-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1267849
- SUSE Bug 1267957
- SUSE CVE CVE-2026-10879 page
- SUSE CVE CVE-2026-9698 page
Описание
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
Затронутые продукты
openSUSE Leap 16.0:perl-DBI-1.647.0-160000.3.1
Ссылки
- CVE-2026-10879
- SUSE Bug 1267849
Описание
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow.
Затронутые продукты
openSUSE Leap 16.0:perl-DBI-1.647.0-160000.3.1
Ссылки
- CVE-2026-9698
- SUSE Bug 1267957