Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24051

Опубликовано: 18 фев. 2022
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mariadbOut of support scope
Red Hat JBoss Core ServicesmariadbNot affected
Red Hat OpenStack Platform 13 (Queens)mariadbOut of support scope
Red Hat Enterprise Linux 8mariadbFixedRHSA-2022:582602.08.2022
Red Hat Enterprise Linux 8mariadbFixedRHSA-2022:644313.09.2022
Red Hat Enterprise Linux 9mariadbFixedRHSA-2022:594809.08.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb105-mariadbFixedRHSA-2022:575928.07.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb103-mariadbFixedRHSA-2022:630601.09.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2068233mariadb: lack of proper validation of a user-supplied string before using it as a format specifier

EPSS

Процентиль: 21%
0.00065
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

CVSS3: 7.8
nvd
больше 3 лет назад

MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

CVSS3: 7.8
debian
больше 3 лет назад

MariaDB CONNECT Storage Engine Format String Privilege Escalation Vuln ...

CVSS3: 7.8
github
больше 3 лет назад

This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

CVSS3: 7
fstec
больше 3 лет назад

Уязвимость реализации функции CONNECT системы управления базами данных MariaDB, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 21%
0.00065
Низкий

7.8 High

CVSS3