Описание
insufficient validation of binary frm data when opening a table
Impact
MariaDB was insufficiently validating the content of binary frm files it was parsing. Specially constructed invalid frm files could've caused server crashes, OOB reads or writes, and exploited to get a remote code execution.
Patches
Fixed in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2.
Workarounds
To be able to drop a poisoned frm into a datadir one needs to be granted FILE privilege and secure-file-priv must allow access to the datadir. Properly configured server does not allow file level access to the datadir and FILE — a very powerful privilege — is normally granted very sparingly.
References
https://jira.mariadb.org/browse/MDEV-40571
Credits
Reported by pinebudweiser and Ph4nt0m
Пакеты
mariadb
>=10.6.1, <=10.6.27
10.6.28
mariadb
>=10.11.1, <=10.11.18
10.11.19
mariadb
>=11.4.1, <=11.4.12
11.4.13
mariadb
>=11.8.1, <=11.8.8
11.8.9
mariadb
>=12.3.1, <=12.3.2
12.3.3
mariadb
13.0.1
13.0.2
8 High
CVSS3
Дефекты
8 High
CVSS3