UbuntuUpdates.org

Package "libdbi-perl"

Name: libdbi-perl

Description:

Perl Database Interface (DBI)

Latest version: 1.643-4ubuntu0.1
Release: noble (24.04)
Level: security
Repository: main
Homepage: https://dbi.perl.org/

Links


Download "libdbi-perl"


Other versions of "libdbi-perl" in Noble

Repository Area Version
base main 1.643-4build3
updates main 1.643-4ubuntu0.1

Changelog

Version: 1.643-4ubuntu0.1 2026-06-24 11:07:33 UTC

  libdbi-perl (1.643-4ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: stack buffer overflow
    - debian/patches/CVE-2026-9698.patch: replace static sprintf buffer with
      dynamic newSVpvf formatting in DBI.xs.
    - CVE-2026-9698
  * SECURITY UPDATE: heap buffer overflow
    - debian/patches/CVE-2026-10879.patch: increases buffer allocation size to
      safely accommodate multi-digit placeholder expansion in DBI.xs.
    - CVE-2026-10879

 -- Ian Constantin <email address hidden> Mon, 22 Jun 2026 10:05:12 +0300

CVE-2026-9698 DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleEr
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL pla



About   -   Send Feedback to @ubuntu_updates