First published: Fri Aug 19 2016(Updated: )
Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
dbd-mysql | =4.033 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8949 has a medium severity rating due to its potential impact on application stability.
To fix CVE-2015-8949, upgrade to DBD::mysql version 4.033_01 or later.
CVE-2015-8949 affects DBD::mysql version prior to 4.033_01 and Debian GNU/Linux version 8.0.
CVE-2015-8949 is caused by a use-after-free issue in the my_login function in DBD::mysql.
Yes, CVE-2015-8949 could potentially be exploited by attackers leveraging specific MySQL function calls.