Updated mariadb packages fix security vulnerability
Publication date: 07 Jul 2020Modification date: 07 Jul 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-2752 , CVE-2020-2760 , CVE-2020-2812 , CVE-2020-2814
Description
Updated mariadb packages fix security vulnerabilities: Vulnerability in the MariaDB Client product of MariaDB (component: C API) Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MariaDB Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MariaDB Client (CVE-2020-2752). Vulnerability in the MariaDB Server product of MariaDB (component: InnoDB). Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MariaDB Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MariaDB Server as well as unauthorized update, insert or delete access to some of MariaDB Server accessible data (CVE-2020-2760). Vulnerability in the MariaDB Server product of MariaDB (component: Server: Stored Procedure). Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MariaDB Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MariaDB Server (CVE-2020-2812). Vulnerability in the MariaDB Server product of MariaDB (component: InnoDB). Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MariaDB Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MariaDB Server (CVE-2020-2814).
References
- https://bugs.mageia.org/show_bug.cgi?id=26818
- https://mariadb.com/kb/en/mariadb-10323-release-notes/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2752
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2760
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2812
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2814
SRPMS
7/core
- mariadb-10.3.23-1.mga7