Описание
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | pending | 1.648-1 |
| esm-infra-legacy/trusty | released | 1.630-1ubuntu0.1~esm6 |
| esm-infra-legacy/xenial | released | 1.634-1ubuntu0.2+esm2 |
| esm-infra/bionic | released | 1.640-1ubuntu0.3+esm1 |
| esm-infra/focal | released | 1.643-1ubuntu0.1+esm1 |
| jammy | released | 1.643-3ubuntu0.1 |
| noble | released | 1.643-4ubuntu0.1 |
| questing | released | 1.647-1ubuntu0.25.10.1 |
| resolute | released | 1.647-1ubuntu0.26.04.1 |
| upstream | released | 1.648-1 |
Показывать по
Ссылки на источники
9.8 Critical
CVSS3
Связанные уязвимости
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
DBI versions before 1.648 for Perl have a heap overflow when preparsin ...
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.
9.8 Critical
CVSS3