Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-27377

Опубликовано: 12 апр. 2022
Источник: debian

Описание

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mariadb-10.6fixed1:10.6.8-1package
mariadb-10.5removedpackage
mariadb-10.5fixed1:10.5.18-0+deb11u1bullseyepackage
mariadb-10.3removedpackage
mariadb-10.1not-affectedpackage

Примечания

  • https://jira.mariadb.org/browse/MDEV-26281

  • Commit MariaDB: https://github.com/MariaDB/server/commit/4681b6f2d8c82b4ec5cf115e83698251963d80d5 (10.2.44)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

CVSS3: 7.5
redhat
почти 4 года назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

CVSS3: 7.5
nvd
около 3 лет назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

CVSS3: 7.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 7.5
github
около 3 лет назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.