Mageia 2020-0284: mariadb security update
Summary
Updated mariadb packages fix security vulnerabilities:
Vulnerability in the MariaDB Client product of MariaDB (component: C API)
Difficult to exploit vulnerability allows low privileged attacker with
network access via multiple protocols to compromise MariaDB Client.
Successful attacks of this vulnerability can result in unauthorized ability
to cause a hang or frequently repeatable crash (complete DOS) of MariaDB
Client (CVE-2020-2752).
Vulnerability in the MariaDB Server product of MariaDB (component: InnoDB).
Easily exploitable vulnerability allows high privileged attacker with network
access via multiple protocols to compromise MariaDB Server. Successful attacks
of this vulnerability can result in unauthorized ability to cause a hang or
frequently repeatable crash (complete DOS) of MariaDB Server as well as
unauthorized update, insert or delete access to some of MariaDB Server
accessible data (CVE-2020-2760).
Vulnerability in the MariaDB Server product of MariaDB (component: Serv...
References
- https://bugs.mageia.org/show_bug.cgi?id=26818
- https://mariadb.com/kb/en/mariadb-10323-release-notes/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2752
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2760
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2812
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2814
Resolution
MGASA-2020-0284 - Updated mariadb packages fix security vulnerability
SRPMS
- 7/core/mariadb-10.3.23-1.mga7