{"id":"CVE-2016-1251","details":"There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.","modified":"2026-04-16T01:42:24.234019641Z","published":"2016-11-29T20:59:00.170Z","related":["SUSE-SU-2017:0025-1","SUSE-SU-2017:0123-1","openSUSE-SU-2024:10186-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0000_0"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0000_0:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0001_1"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0001_1:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0001_2:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"3.0001_2"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0001_3"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0001_3:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0002_1"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0002_1:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0002_2:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"3.0002_2"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0002_3"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0002_3:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0002_4:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"3.0002_4"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0002_5:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"3.0002_5"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0003_1"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0003_1:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0004_1"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0004_1:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0005"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0005:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0005_1"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0005_1:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0007_2:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"3.0007_2"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"3.0008_1"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0008_1:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:3.0009_1:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"3.0009_1"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.001"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.001:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.002:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"4.002"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.003"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.003:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.004"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.004:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.005"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.005:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.006:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"4.006"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.007"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.007:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.008"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.008:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.009:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"4.009"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.00:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"4.00"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.010"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.010:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.011:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"4.011"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.016"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.016:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.017"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.017:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.018"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.018:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.023:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"4.023"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.024"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.024:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.025:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"4.025"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.026"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.026:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.027"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.027:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.028:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"4.028"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.029:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"4.029"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"last_affected":"4.039"}],"cpe":"cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.039:*:*:*:*:*:*:*"}]},"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/11/28/2"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/94573"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201701-51"},{"type":"ADVISORY","url":"https://tracker.debian.org/news/819888"},{"type":"FIX","url":"https://anonscm.debian.org/cgit/pkg-perl/packages/libdbd-mysql-perl.git/commit/?id=a8b97e4713391b1f8beffbfddac483c276feaff1"},{"type":"FIX","url":"https://github.com/perl5-dbi/DBD-mysql/commit/3619c170461a3107a258d1fd2d00ed4832adb1b1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/perl5-dbi/dbd-mysql","events":[{"introduced":"0"},{"last_affected":"6a18c6bbe7474e363c1020c74f0c19758f2ba519"},{"last_affected":"a82a5dd324d7eaa508d372a350a7d667ea2c4ce0"},{"last_affected":"6e296abd775e9eb8a130407e02330c90aad85b92"},{"last_affected":"e0251b691f6f1d7373fe1829ed02326d79a2943c"},{"last_affected":"538953a6b4744efd79e6e6d6cbf6cdbfedc26baf"},{"last_affected":"aae097ee1364ca3d0fad09671fd9729ab5128aeb"},{"last_affected":"40ae039419b408e060255627acfa0eed65c5f6dd"},{"last_affected":"5acbdcb88d580d6376da3b96eedf517bcb5bfcb9"},{"last_affected":"454e09f12226b67401162fae6323d016c1480f1f"},{"last_affected":"5fb6dd06e84da42933477998bfdae2820168a3c3"},{"last_affected":"c33e4cd4a423b946acea22309367ba742c53f9ab"},{"last_affected":"bd46c959e98da7d4cc0563cc6d32a71a85493dce"},{"last_affected":"f1e6168136af44a06f0c10cc95a0cf3b6ffbd58f"},{"last_affected":"1ec96de4d35309278b74f6127f9e42c82007564d"},{"last_affected":"53fe41ce23ce779af567c9ed802bd6c3ba478770"},{"last_affected":"ceee88b24f62920bc01adeec6b0e1870bfb51ec4"},{"last_affected":"b37240e0fd2ca0031429164231824ea02775dc9e"},{"last_affected":"cae30cf640683802fdd9b5aec6a3296c046411a8"},{"last_affected":"5504e3ab6ec9d04b9263c73719b481065a9f81bb"},{"last_affected":"34ec497b56cebf72fead9c6f7490823e793d24c5"},{"last_affected":"122b6d6ecdcf655e8c46a5bddfd0502e7987487b"},{"last_affected":"b00ba254e7fbea60b47c08a6242810abde85cab4"},{"last_affected":"48d0dec4e985fbc59def70ac10042ebbb31b1d00"},{"last_affected":"cb385624b41a0f233838ed75a6965261a124cd8d"},{"last_affected":"9162255af21aded87b597d1ce98e3f8cbe835dff"},{"last_affected":"394a952a24b0025d3c70596420de625db1951a8a"},{"last_affected":"988368c7c14b48cadc5459c0725f1d9540ce1ede"},{"last_affected":"aa193b663168120ec893f5c0fadaf1acf5abd19e"},{"last_affected":"7e3a83d1da5f5a554be14fef4302cd72759b8696"},{"last_affected":"ebdd95e4bea5c1de510f145c92be2d917bd263a1"}],"database_specific":{"cpe":["cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.012:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.013:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.014:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.015:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.019:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.020:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.021:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.022:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.030_01:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.030_02:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.031:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.032:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.032_01:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.032_02:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.032_03:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.033:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.033_01:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.033_02:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.033_03:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.034:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.035:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.035_01:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.035_02:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.035_03:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.036:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.037:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.037_01:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.038:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.038_01:*:*:*:*:*:*:*","cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.040:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"4.012"},{"last_affected":"4.013"},{"last_affected":"4.014"},{"last_affected":"4.015"},{"last_affected":"4.019"},{"last_affected":"4.020"},{"last_affected":"4.021"},{"last_affected":"4.022"},{"last_affected":"4.030_01"},{"last_affected":"4.030_02"},{"last_affected":"4.031"},{"last_affected":"4.032"},{"last_affected":"4.032_01"},{"last_affected":"4.032_02"},{"last_affected":"4.032_03"},{"last_affected":"4.033"},{"last_affected":"4.033_01"},{"last_affected":"4.033_02"},{"last_affected":"4.033_03"},{"last_affected":"4.034"},{"last_affected":"4.035"},{"last_affected":"4.035_01"},{"last_affected":"4.035_02"},{"last_affected":"4.035_03"},{"last_affected":"4.036"},{"last_affected":"4.037"},{"last_affected":"4.037_01"},{"last_affected":"4.038"},{"last_affected":"4.038_01"},{"last_affected":"4.040"}],"source":"CPE_FIELD"}}],"versions":["4.030_01","4.030_02","4.031","4.032","4.032_01","4.032_02","4.032_03","4.033","4.033_01","4.033_02","4.033_03","4.034","4.035","4.035_01","4.035_02","4.035_03","4.036","4.037","4.037_01","4.037_02","4.038","4.038_01","4.040","4_012","4_013","4_014","4_015","4_019","4_020","4_021","4_022","4_022_1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-1251.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}