1 |
type: security |
2 |
subject: Updated mariadb packages fix security vulnerability |
3 |
CVE: |
4 |
- CVE-2019-2614 |
5 |
- CVE-2019-2627 |
6 |
src: |
7 |
6: |
8 |
core: |
9 |
- mariadb-10.1.39-1.mga6 |
10 |
description: | |
11 |
Vulnerability in the MariaDB Server component of MariaDB (subcomponent: |
12 |
Server: Replication). Difficult to exploit vulnerability allows high |
13 |
privileged attacker with network access via multiple protocols to |
14 |
compromise MariaDB Server. Successful attacks of this vulnerability can |
15 |
result in unauthorized ability to cause a hang or frequently repeatable |
16 |
crash (complete DOS) of MariaDB Server (CVE-2019-2614). |
17 |
|
18 |
Vulnerability in the MariaDB Server component of MariaDB (subcomponent: |
19 |
Server: Security: Privileges). Easily exploitable vulnerability allows |
20 |
high privileged attacker with network access via multiple protocols to |
21 |
compromise MariaDB Server. Successful attacks of this vulnerability can |
22 |
result in unauthorized ability to cause a hang or frequently repeatable |
23 |
crash (complete DOS) of MariaDB Server (CVE-2019-2627). |
24 |
references: |
25 |
- https://bugs.mageia.org/show_bug.cgi?id=24743 |
26 |
- https://mariadb.com/kb/en/library/mariadb-10139-release-notes/ |
27 |
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html#AppendixMSQL |
28 |
ID: MGASA-2019-0181 |