Debian alert DLA-4649-1 (libdbi-perl)
| From: | Guilhem Moulin <guilhem@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4649-1] libdbi-perl security update | |
| Date: | Fri, 26 Jun 2026 06:59:23 +0200 | |
| Message-ID: | <aj4HK-3S_pQJYvLC@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4649-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin June 26, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libdbi-perl Version : 1.643-3+deb11u1 CVE ID : CVE-2026-9698 CVE-2026-10879 Two vulnerabilities were discovered in libdbi-perl, the Perl Database Interface (DBI), which may lead to denial of service or potentially execution of arbitrary code. CVE-2026-9698 Error messages that were returned when `RaiseError`, `PrintError` or `HandleError` were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application could therefore trigger a buffer overflow. CVE-2026-10879 The preparse method expands SQL placeholder characters to numbered binders of the form `:pN`, but only allocates three characters per binder in the buffer, leading to an out-of-bounds write when the statement has 10 or more binders. For Debian 11 bullseye, these problems have been fixed in version 1.643-3+deb11u1. We recommend that you upgrade your libdbi-perl packages. For the detailed security status of libdbi-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libdbi-perl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmo+BysACgkQ05pJnDwh pVL9ng/+NPlKsbIWZzPnIrKqvxYHgL4NbXEhY6GnOQctIgrWRjGoDvuTB4Z8OHkr dIH6bCaX8JmBEiM3uR91hPdEt8XAS2EOIz1752oR/3MxRpdJ4RrLj7stAJobZBNC EKNeAuLoZ64ZLpEorLvsDnoAm0PhGwBFQW2yKN7ViP+W4QRgmJoe1TvKVbv3bhHc UnpQVe6oOxhIncoOFIaBHAI09v9/2444s6rfDOxVLms1k47BAnba+2QuZXArvlUM 03u+QMwHtENtxQKkfnByqEzqGwoFpcK97bYb/7CtG6ddKU2BArev5//JZWXU9ORZ z3eibDiawIJftISp2/zncdrppiNc/PrCx/y0ClWxeH+Rz6UtBfFKeWcfNddq1LLq OZXGviKwfX+kwDQXWgZPtUKLliKpa43scn4iBn11DE8aNeFktVdW6wzNJEpG54KB 5AjZQlFLKZ3/0liOGzJDEdhKwnVz0w/3md7Z40LSMT3dRF+KueS9BYOlYNsuaTvI 7m7I7wg9tCS2Cr1Shp6nW6gn0zoGmYBKVbB3EG5z3mwdcruE7mFtkgtKI4zyoTUr UX+wvfGEP5Ra8l8t7CdSylTq5Sl4Nh3eua3dB1Q2s4p5q8fmCeU6puHBO9k69XaA tKpC5PU+2B5v2uJJfvirUlXzOv+UwNgMM2SIkY3jCtj2jfuoTKk= =LOJg -----END PGP SIGNATURE-----
