Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 7: MGASA-2019-0335 Moderate: MariaDB Denial Of Service

mageia
Calendar Grey November 19, 2019
Dist Mageia Esm H88
Updated MariaDB packages resolve Medium security issues as detailed in MGASA-2019-0335. Published on 19 Nov 2019.
Updated mariadb packages fix security vulnerabilities: A vulnerability in Server: Optimizer contains an easily exploitable vulnerability allows low privileged attacker with networ...

Summary

Updated mariadb packages fix security vulnerabilities:
A vulnerability in Server: Optimizer contains an easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise the server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) (CVE-2019-2974).
A vulnerability in InnoDB contains an Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise the server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) (CVE-2019-2938).

References

- https://bugs.mageia.org/show_bug.cgi?id=25691

- https://www.cve.org/CVERecord?id=CVE-2019-2974

- https://www.cve.org/CVERecord?id=CVE-2019-2938

Resolution

SRPMS

- 7/core/mariadb-10.3.20-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 19 Nov 2019
URL: https://advisories.mageia.org/MGASA-2019-0335.html
Type: security
CVE: CVE-2019-2974, CVE-2019-2938

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here