Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: 2018:1450-1 Moderate: perl-DBD-mysql DoS and Downgrade Threats

suse
Calendar Grey May 28, 2018
Scroller Suse
SUSE Security Update for perl-DBD-pgsql addresses critical injection and denial-of-service vulnerabilities. Essential information and patch instructions included.
An update that fixes two vulnerabilities is now available

Summary

This update for perl-DBD-mysql fixes the following issues: - CVE-2017-10789: The DBD::mysql module when with mysql_ssl=1 setting enabled, means that SSL is optional (even though this setting's documentation has a \"your communication with the server will be encrypted\" statement), which could lead man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152. (bsc#1047059) - CVE-2017-10788: The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free defect was

References

#1047059 #1047095

Cross- CVE-2017-10788 CVE-2017-10789

Affected Products:

SUSE Linux Enterprise Server 12-SP3

https://www.suse.com/security/cve/CVE-2017-10788.html

https://www.suse.com/security/cve/CVE-2017-10789.html

https://bugzilla.suse.com/1047059

https://bugzilla.suse.com/1047095

Announcement ID: SUSE-SU-2018:1450-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.