MGASA-2021-0402

Source
https://advisories.mageia.org/MGASA-2021-0402.html
Import Source
https://advisories.mageia.org/MGASA-2021-0402.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0402
Related
Published
2021-08-14T14:00:09Z
Modified
2021-08-14T13:29:19Z
Summary
Updated mariadb packages fix security vulnerabilities
Details

Updated mariadb packages fix security vulnerabilities:

A security issue has been found in the InnoDB component of MariaDB before version 10.6.4. A difficult to exploit vulnerability allows a high privileged attacker with network access via multiple protocols to compromise the MariaDB server. Successful attacks of this vulnerability can result in the unauthorized ability to cause a hang or frequently repeatable crash (complete denial of service) of the MariaDB server (CVE-2021-2372).

A security issue has been found in the InnoDB component of MariaDB before version 10.6.4. A difficult to exploit vulnerability allows an unauthenticated attacker with network access via multiple protocols to compromise the MariaDB server. Successful attacks of this vulnerability can result in the unauthorized ability to cause a hang or frequently repeatable crash (complete denial of service) of the MariaDB server (CVE-2021-2389).

References
Credits

Affected packages

Mageia:8 / mariadb

Package

Name
mariadb
Purl
pkg:rpm/mageia/mariadb?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.5.12-1.mga8

Ecosystem specific

{
    "section": "core"
}