CVE-2015-8949: Use After Free
Published Aug 19, 2016
·Updated
Use-after-free vulnerability in the mylogin function in DBD::mysql before 4.03301 allows attackers to have unspecified impact by leveraging a call to mysqlerrno after a failure of mylogin.
Affected Software
2 affected components
Dbd-mysql Project Dbd-mysql=4.033
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Aug 19, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8949?
CVE-2015-8949 has a medium severity rating due to its potential impact on application stability.
2
How do I fix CVE-2015-8949?
To fix CVE-2015-8949, upgrade to DBD::mysql version 4.033_01 or later.
3
What systems are affected by CVE-2015-8949?
CVE-2015-8949 affects DBD::mysql version prior to 4.033_01 and Debian GNU/Linux version 8.0.
4
What causes the CVE-2015-8949 vulnerability?
CVE-2015-8949 is caused by a use-after-free issue in the my_login function in DBD::mysql.
5
Can CVE-2015-8949 be exploited remotely?
Yes, CVE-2015-8949 could potentially be exploited by attackers leveraging specific MySQL function calls.