security advisoryDebianremote execution
A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. An attacker could generate a malicious dump file which could execute shell commands from the MariaDB client. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3891-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Otto Kekäläinen September 18, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : mariadb-10.5 Version : 1:10.5.26-0+deb11u2 CVE ID : CVE-2024-21096 Debian Bug : 1069189 1015293 A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. An attacker could generate a malicious dump file which could execute shell commands from the MariaDB client. The fix may cause a compatibility issue with older MariaDB and MySQL clients, with existing workarounds, as detailed at: https://mariadb.org/mariadb-dump-file-compatibility-change/ This updates also includes bugfixes through the 10.5 maintenance branch, as detailed at: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-24-release-notes https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-25-release-notes https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-26-release-notes For Debian 11 bullseye, this problem has been fixed in version 1:10.5.26-0+deb11u2. We recommend that you upgrade your mariadb-10.5 packages. For the detailed security status of mariadb-10.5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mariadb-10.5 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A pressingalert for Debian LTS concerning a security vulnerability in MariaDB, which permits unauthorized remote execution of shell commands.. MariaDB, SQL Database, Debian LTS, Security Advisory, Remote Execution. . Severity: Critical. LinuxSecurity.com Team
Sep 18, 2024
•Critical
Debian LTS