A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrepprovider and wsrepnotify_cmd. NOTE: this does not affect an Oracle product.
{
"binaries": [
{
"binary_name": "percona-server-server",
"binary_version": "5.6.22-rel71.0-0ubuntu4.1"
},
{
"binary_name": "percona-server-server-5.6",
"binary_version": "5.6.22-rel71.0-0ubuntu4.1"
},
{
"binary_name": "percona-server-source-5.6",
"binary_version": "5.6.22-rel71.0-0ubuntu4.1"
},
{
"binary_name": "percona-server-test",
"binary_version": "5.6.22-rel71.0-0ubuntu4.1"
},
{
"binary_name": "percona-server-test-5.6",
"binary_version": "5.6.22-rel71.0-0ubuntu4.1"
}
]
}
{
"binaries": [
{
"binary_name": "libmariadbclient-dev",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "libmariadbclient-dev-compat",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "libmariadbclient18",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "libmariadbd-dev",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "libmariadbd18",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-client",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-client-10.1",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-client-core-10.1",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-common",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-plugin-connect",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-plugin-cracklib-password-check",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-plugin-gssapi-client",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-plugin-gssapi-server",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-plugin-mroonga",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-plugin-oqgraph",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-plugin-spider",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-plugin-tokudb",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-server",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-server-10.1",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-server-core-10.1",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-test",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
},
{
"binary_name": "mariadb-test-data",
"binary_version": "1:10.1.48-0ubuntu0.18.04.1"
}
]
}
{
"binaries": [
{
"binary_name": "libmariadb-dev",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "libmariadb-dev-compat",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "libmariadb3",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "libmariadbclient-dev",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "libmariadbd-dev",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "libmariadbd19",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-backup",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-client",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-client-10.3",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-client-core-10.3",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-common",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-plugin-connect",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-plugin-cracklib-password-check",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-plugin-gssapi-client",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-plugin-gssapi-server",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-plugin-mroonga",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-plugin-oqgraph",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-plugin-rocksdb",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-plugin-spider",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-plugin-tokudb",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-server",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-server-10.3",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-server-core-10.3",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-test",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
},
{
"binary_name": "mariadb-test-data",
"binary_version": "1:10.3.39-0ubuntu0.20.04.2"
}
]
}