1 |
davidwhodgins |
8468 |
type: security |
2 |
|
|
subject: Updated mariadb packages fix security vulnerability |
3 |
|
|
CVE: |
4 |
|
|
- CVE-2019-2529 |
5 |
|
|
- CVE-2019-2537 |
6 |
|
|
src: |
7 |
|
|
6: |
8 |
|
|
core: |
9 |
|
|
- mariadb-10.1.38-1.mga6 |
10 |
|
|
description: | |
11 |
|
|
Vulnerability in the MariaDB Server component of MariaDB (subcomponent: Server: |
12 |
|
|
Optimizer). Easily exploitable vulnerability allows low privileged attacker |
13 |
|
|
with network access via multiple protocols to compromise MariaDB Server. |
14 |
|
|
Successful attacks of this vulnerability can result in unauthorized ability to |
15 |
|
|
cause a hang or frequently repeatable crash (complete DOS) of MariaDB Server |
16 |
|
|
(CVE-2019-2529). |
17 |
|
|
|
18 |
|
|
Vulnerability in the MariaDB Server component of MariaDB (subcomponent: Server: |
19 |
|
|
DDL). Easily exploitable vulnerability allows high privileged attacker with |
20 |
|
|
network access via multiple protocols to compromise MariaDB Server. Successful |
21 |
|
|
attacks of this vulnerability can result in unauthorized ability to cause a |
22 |
|
|
hang or frequently repeatable crash (complete DOS) of MariaDB Server |
23 |
|
|
(CVE-2019-2537). |
24 |
|
|
references: |
25 |
|
|
- https://bugs.mageia.org/show_bug.cgi?id=24624 |
26 |
|
|
- https://mariadb.com/kb/en/library/mariadb-10138-release-notes/ |
27 |
|
|
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html |
28 |
tmb |
8473 |
ID: MGASA-2019-0147 |