Описание
Use-after-free with a large number of SYS_REFCURSOR's
Impact
When a large number of SYS_REFCURSOR's are opened and then one of them is fetched, it is possible to trigger a use-after-free condition. It could be used in a multi-vulnerability exploitation chain (combined with, for example, this vulnerability for a full remote code execution exploitation.
Patches
Fixed in 12.3.3, 13.0.2.
Workarounds
There is no workaround. Users are advised to upgrade immediately.
References
https://jira.mariadb.org/browse/MDEV-40396 https://jira.mariadb.org/browse/MDEV-40639
Credits
Reported by Rick de Jager from v12 security Reported by Akhil Koul
Пакеты
Наименование
mariadb
mariadb
Затронутые версииВерсия исправления
>=12.3.1, <=12.3.2
12.3.3
Наименование
mariadb
mariadb
Затронутые версииВерсия исправления
13.0.1
13.0.2