Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44172

Опубликовано: 12 июн. 2026
Источник: debian
EPSS Низкий

Описание

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mariadbfixed1:11.8.8-1package
mariadbno-dsatrixiepackage
mariadbfixed1:10.11.18-0+deb12u1bookwormpackage

Примечания

  • https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7

  • https://github.com/MariaDB/server/security/advisories/GHSA-pv9p-5w55-55jm

  • https://jira.mariadb.org/browse/CONC-819

EPSS

Процентиль: 24%
0.00316
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

CVSS3: 9.1
redhat
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

CVSS3: 9.1
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

suse-cvrf
9 дней назад

Security update for mariadb-connector-c

suse-cvrf
11 дней назад

Security update for mariadb-connector-c

EPSS

Процентиль: 24%
0.00316
Низкий