CVE-2016-1251

high
Published 2016-11-29 ยท Modified 2026-05-06
CVSS v3
8.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.1

Description

There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.

Predictions

Exploit likelihood
88%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed4.041-1
debian debianbullseyefixed4.041-1
debian debianforkyfixed4.041-1
debian debiansidfixed4.041-1
debian debiantrixiefixed4.041-1

Application impact

VendorProductVersionsFixed
dbd-mysql_projectdbd-mysql3.0000_0
dbd-mysql_projectdbd-mysql3.0001_1
dbd-mysql_projectdbd-mysql3.0001_2
dbd-mysql_projectdbd-mysql3.0001_3
dbd-mysql_projectdbd-mysql3.0002_1
dbd-mysql_projectdbd-mysql3.0002_2
dbd-mysql_projectdbd-mysql3.0002_3
dbd-mysql_projectdbd-mysql3.0002_4
dbd-mysql_projectdbd-mysql3.0002_5
dbd-mysql_projectdbd-mysql3.0003_1
dbd-mysql_projectdbd-mysql3.0004_1
dbd-mysql_projectdbd-mysql3.0005
dbd-mysql_projectdbd-mysql3.0005_1
dbd-mysql_projectdbd-mysql3.0007_2
dbd-mysql_projectdbd-mysql3.0008_1
dbd-mysql_projectdbd-mysql3.0009_1
dbd-mysql_projectdbd-mysql4.00
dbd-mysql_projectdbd-mysql4.001
dbd-mysql_projectdbd-mysql4.002
dbd-mysql_projectdbd-mysql4.003
dbd-mysql_projectdbd-mysql4.004
dbd-mysql_projectdbd-mysql4.005
dbd-mysql_projectdbd-mysql4.006
dbd-mysql_projectdbd-mysql4.007
dbd-mysql_projectdbd-mysql4.008
dbd-mysql_projectdbd-mysql4.009
dbd-mysql_projectdbd-mysql4.010
dbd-mysql_projectdbd-mysql4.011
dbd-mysql_projectdbd-mysql4.012
dbd-mysql_projectdbd-mysql4.013
dbd-mysql_projectdbd-mysql4.014
dbd-mysql_projectdbd-mysql4.015
dbd-mysql_projectdbd-mysql4.016
dbd-mysql_projectdbd-mysql4.017
dbd-mysql_projectdbd-mysql4.018
dbd-mysql_projectdbd-mysql4.019
dbd-mysql_projectdbd-mysql4.020
dbd-mysql_projectdbd-mysql4.021
dbd-mysql_projectdbd-mysql4.022
dbd-mysql_projectdbd-mysql4.023
dbd-mysql_projectdbd-mysql4.024
dbd-mysql_projectdbd-mysql4.025
dbd-mysql_projectdbd-mysql4.026
dbd-mysql_projectdbd-mysql4.027
dbd-mysql_projectdbd-mysql4.028
dbd-mysql_projectdbd-mysql4.029
dbd-mysql_projectdbd-mysql4.030_01
dbd-mysql_projectdbd-mysql4.030_02
dbd-mysql_projectdbd-mysql4.031
dbd-mysql_projectdbd-mysql4.032
dbd-mysql_projectdbd-mysql4.032_01
dbd-mysql_projectdbd-mysql4.032_02
dbd-mysql_projectdbd-mysql4.032_03
dbd-mysql_projectdbd-mysql4.033
dbd-mysql_projectdbd-mysql4.033_01
dbd-mysql_projectdbd-mysql4.033_02
dbd-mysql_projectdbd-mysql4.033_03
dbd-mysql_projectdbd-mysql4.034
dbd-mysql_projectdbd-mysql4.035
dbd-mysql_projectdbd-mysql4.035_01
dbd-mysql_projectdbd-mysql4.035_02
dbd-mysql_projectdbd-mysql4.035_03
dbd-mysql_projectdbd-mysql4.036
dbd-mysql_projectdbd-mysql4.037
dbd-mysql_projectdbd-mysql4.037_01
dbd-mysql_projectdbd-mysql4.038
dbd-mysql_projectdbd-mysql4.038_01
dbd-mysql_projectdbd-mysql4.039
dbd-mysql_projectdbd-mysql4.040

References

CWEs

CWE-416

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.