4.3
CVSSv2

CVE-2016-1249

Published: 17/02/2017 Updated: 09/08/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The DBD::mysql module prior to 4.039 for Perl, when using server-side prepared statement support, allows malicious users to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dbd-mysql project dbd-mysql

Vendor Advisories

Debian Bug report logs - #844475 CVE-2016-1249: Out-of-bounds read by DBD::mysql Package: libdbd-mysql-perl; Maintainer for libdbd-mysql-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libdbd-mysql-perl is src:libdbd-mysql-perl (PTS, buildd, popcon) Reported by: Henri Salo <henri@nerv ...
The DBD::mysql module before 4039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression ...