[Bug 1877409] CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name

2021-11-02 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1877409

Todd Cullum  changed:

   What|Removed |Added

 Status|NEW |CLOSED
 Resolution|--- |WONTFIX
Last Closed||2021-11-02 17:26:38




-- 
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1877409
___
perl-devel mailing list -- perl-devel@lists.fedoraproject.org
To unsubscribe send an email to perl-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/perl-devel@lists.fedoraproject.org
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure


[Bug 1877409] CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name

2021-02-22 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1877409


--- Doc Text *updated* by RaTasha Tillery-Smith  ---
A buffer overflow was found in perl-DBI before version 1.643 in DBI.xs. This 
flaw allows a local attacker who can supply a string longer than 300 characters 
to cause an out-of-bounds write. The highest threat from this vulnerability is 
to integrity and system availability.



-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
perl-devel mailing list -- perl-devel@lists.fedoraproject.org
To unsubscribe send an email to perl-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/perl-devel@lists.fedoraproject.org
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure


[Bug 1877409] CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name

2020-09-28 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1877409



--- Comment #5 from Todd Cullum  ---
Marked the CVSS score as 4.4 for products as there would only be a temporary
risk to availability and low risk to data integrity due to binary protections
shipped with the products.


-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
perl-devel mailing list -- perl-devel@lists.fedoraproject.org
To unsubscribe send an email to perl-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/perl-devel@lists.fedoraproject.org


[Bug 1877409] CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name

2020-09-25 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1877409
Bug 1877409 depends on bug 1877410, which changed state.

Bug 1877410 Summary: CVE-2020-14393 perl-DBI: Buffer overlfow on an overlong 
DBD class name [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1877410

   What|Removed |Added

 Status|ON_QA   |CLOSED
 Resolution|--- |ERRATA




-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
perl-devel mailing list -- perl-devel@lists.fedoraproject.org
To unsubscribe send an email to perl-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/perl-devel@lists.fedoraproject.org


[Bug 1877409] CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name

2020-09-10 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1877409



--- Comment #4 from Todd Cullum  ---
External References:

Advisory:
https://metacpan.org/pod/distribution/DBI/Changes#Changes-in-DBI-1.643-...


-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
perl-devel mailing list -- perl-devel@lists.fedoraproject.org
To unsubscribe send an email to perl-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/perl-devel@lists.fedoraproject.org


[Bug 1877409] CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name

2020-09-10 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1877409

Todd Cullum  changed:

   What|Removed |Added

 Depends On||1877959, 1877956, 1877957,
   ||1877958




-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
perl-devel mailing list -- perl-devel@lists.fedoraproject.org
To unsubscribe send an email to perl-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/perl-devel@lists.fedoraproject.org


[Bug 1877409] CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name

2020-09-10 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1877409


--- Doc Text *updated* by Todd Cullum  ---
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who 
is able to supply a string longer than 300 characters could cause an 
out-of-bounds write, affecting the availability of the service or integrity of 
data.



-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
perl-devel mailing list -- perl-devel@lists.fedoraproject.org
To unsubscribe send an email to perl-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/perl-devel@lists.fedoraproject.org


[Bug 1877409] CVE-2020-14393 perl-dbi: Buffer overflow on an overlong DBD class name

2020-09-09 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1877409

Tomas Hoger  changed:

   What|Removed |Added

Summary|CVE-2020-14393 perl-dbi:|CVE-2020-14393 perl-dbi:
   |Buffer overlfow on an   |Buffer overflow on an
   |overlong DBD class name |overlong DBD class name




-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
perl-devel mailing list -- perl-devel@lists.fedoraproject.org
To unsubscribe send an email to perl-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/perl-devel@lists.fedoraproject.org