1 |
type: security |
2 |
subject: Updated mariadb packages fix security vulnerability |
3 |
CVE: |
4 |
- CVE-2019-2529 |
5 |
- CVE-2019-2537 |
6 |
src: |
7 |
6: |
8 |
core: |
9 |
- mariadb-10.1.38-1.mga6 |
10 |
description: | |
11 |
Vulnerability in the MariaDB Server component of MariaDB (subcomponent: Server: |
12 |
Optimizer). Easily exploitable vulnerability allows low privileged attacker |
13 |
with network access via multiple protocols to compromise MariaDB Server. |
14 |
Successful attacks of this vulnerability can result in unauthorized ability to |
15 |
cause a hang or frequently repeatable crash (complete DOS) of MariaDB Server |
16 |
(CVE-2019-2529). |
17 |
|
18 |
Vulnerability in the MariaDB Server component of MariaDB (subcomponent: Server: |
19 |
DDL). Easily exploitable vulnerability allows high privileged attacker with |
20 |
network access via multiple protocols to compromise MariaDB Server. Successful |
21 |
attacks of this vulnerability can result in unauthorized ability to cause a |
22 |
hang or frequently repeatable crash (complete DOS) of MariaDB Server |
23 |
(CVE-2019-2537). |
24 |
references: |
25 |
- https://bugs.mageia.org/show_bug.cgi?id=24624 |
26 |
- https://mariadb.com/kb/en/library/mariadb-10138-release-notes/ |
27 |
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html |
28 |
ID: MGASA-2019-0147 |