Описание
Numerous issues caused by historical #mysql50# tablename encoding bypass
Impact
Normally MariaDB encodes tables names when storing them on the filesystem, e.g. table a-b is stored in files a@002db (plus some extension). A #mysql50# bypass prefix allows to access tables that were created in MySQL 5.0, before this encoding was implemented, a name #mysql50#a-b corresponds to the table stored in files a-b (plus extension).
There were numerous vulnerabilities related to this historical encoding bypass, including, but not limited to, crashes, data corruption, data exfiltration and remote code execution.
Patches
Fixed in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2.
Workarounds
There is no workaround. Users are advised to upgrade immediately.
References
https://jira.mariadb.org/browse/MDEV-40362
Credits
Ben Bidner (Automattic.com Security Team)
Пакеты
mariadb
>=10.6.1, <=10.6.27
10.6.28
mariadb
>=10.11.1, <=10.11.18
10.11.19
mariadb
>=11.4.1, <=11.4.12
11.4.13
mariadb
>=11.8.1, <=11.8.8
11.8.9
mariadb
>=12.3.1, <=12.3.2
12.3.3
mariadb
13.0.1
13.0.2
9.9 Critical
CVSS3
CVE ID
9.9 Critical
CVSS3