1 |
davidwhodgins |
8560 |
type: security |
2 |
|
|
subject: Updated mariadb packages fix security vulnerability |
3 |
|
|
CVE: |
4 |
|
|
- CVE-2019-2614 |
5 |
|
|
- CVE-2019-2627 |
6 |
|
|
src: |
7 |
|
|
6: |
8 |
|
|
core: |
9 |
|
|
- mariadb-10.1.39-1.mga6 |
10 |
|
|
description: | |
11 |
|
|
Vulnerability in the MariaDB Server component of MariaDB (subcomponent: |
12 |
|
|
Server: Replication). Difficult to exploit vulnerability allows high |
13 |
|
|
privileged attacker with network access via multiple protocols to |
14 |
|
|
compromise MariaDB Server. Successful attacks of this vulnerability can |
15 |
|
|
result in unauthorized ability to cause a hang or frequently repeatable |
16 |
|
|
crash (complete DOS) of MariaDB Server (CVE-2019-2614). |
17 |
|
|
|
18 |
|
|
Vulnerability in the MariaDB Server component of MariaDB (subcomponent: |
19 |
|
|
Server: Security: Privileges). Easily exploitable vulnerability allows |
20 |
|
|
high privileged attacker with network access via multiple protocols to |
21 |
|
|
compromise MariaDB Server. Successful attacks of this vulnerability can |
22 |
|
|
result in unauthorized ability to cause a hang or frequently repeatable |
23 |
|
|
crash (complete DOS) of MariaDB Server (CVE-2019-2627). |
24 |
|
|
references: |
25 |
|
|
- https://bugs.mageia.org/show_bug.cgi?id=24743 |
26 |
|
|
- https://mariadb.com/kb/en/library/mariadb-10139-release-notes/ |
27 |
|
|
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html#AppendixMSQL |