CVE-2020-13249
20.05.2020, 19:15
libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.Enginsight
Vendor | Product | Version |
---|---|---|
mariadb | connector\/c | 𝑥 < 3.1.8 |
opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mariadb-10.0 |
| ||||||||||||||||||||||||||
mariadb-10.1 |
| ||||||||||||||||||||||||||
mariadb-10.3 |
| ||||||||||||||||||||||||||
mariadb-5.5 |
|
References