Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-13249

Опубликовано: 20 мая 2020
Источник: debian

Описание

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mariadb-10.3fixed1:10.3.23-1package
mariadb-10.3fixed1:10.3.23-0+deb10u1busterpackage
mariadb-10.1not-affectedpackage

Примечания

  • Fixed by: https://github.com/mariadb-corporation/mariadb-connector-c/commit/2759b87d72926b7c9b5426437a7c8dd15ff57945 (v3.1.8)

  • Introduced around: https://github.com/mariadb-corporation/mariadb-connector-c/commit/b4efe73c9e725f97b3550371f8a78a10a20bf2fd (v3.0-cc-server-integ-0)

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 5 лет назад

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

CVSS3: 8.8
redhat
около 5 лет назад

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

CVSS3: 8.8
nvd
около 5 лет назад

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

suse-cvrf
около 5 лет назад

Security update for mariadb-connector-c

suse-cvrf
около 5 лет назад

Security update for mariadb-connector-c