Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13249

Опубликовано: 20 мая 2020
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)mariadbNot affected
Red Hat Enterprise Linux 8mariadbFixedRHSA-2020:550015.12.2020
Red Hat Enterprise Linux 8mariadb-connector-cFixedRHSA-2020:550315.12.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionsmariadb-connector-cFixedRHSA-2020:566222.12.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsmariadbFixedRHSA-2020:566322.12.2020
Red Hat Enterprise Linux 8.1 Extended Update Supportmariadb-connector-cFixedRHSA-2020:566022.12.2020
Red Hat Enterprise Linux 8.1 Extended Update SupportmariadbFixedRHSA-2020:566522.12.2020
Red Hat Enterprise Linux 8.2 Extended Update SupportmariadbFixedRHSA-2020:565422.12.2020
Red Hat Enterprise Linux 8.2 Extended Update Supportmariadb-connector-cFixedRHSA-2020:565522.12.2020
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-mariadb102-galeraFixedRHSA-2020:417405.10.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1839827mariadb-connector-c: Improper validation of content in a OK packet received from server

EPSS

Процентиль: 63%
0.00463
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 5 лет назад

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

CVSS3: 8.8
nvd
около 5 лет назад

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

CVSS3: 8.8
debian
около 5 лет назад

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not ...

suse-cvrf
около 5 лет назад

Security update for mariadb-connector-c

suse-cvrf
около 5 лет назад

Security update for mariadb-connector-c

EPSS

Процентиль: 63%
0.00463
Низкий

8.8 High

CVSS3