CVE-2022-27377
12.04.2022, 20:15
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.Enginsight
Vendor | Product | Version |
---|---|---|
mariadb | mariadb | 10.2.0 ≤ 𝑥 < 10.2.44 |
mariadb | mariadb | 10.3.0 ≤ 𝑥 < 10.3.35 |
mariadb | mariadb | 10.4.0 ≤ 𝑥 < 10.4.25 |
mariadb | mariadb | 10.5.0 ≤ 𝑥 < 10.5.16 |
mariadb | mariadb | 10.6.0 ≤ 𝑥 < 10.6.8 |
mariadb | mariadb | 10.7.0 ≤ 𝑥 < 10.7.4 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mariadb-10.0 |
| ||||||||||||||
mariadb-10.1 |
| ||||||||||||||
mariadb-10.3 |
| ||||||||||||||
mariadb-10.5 |
| ||||||||||||||
mariadb-10.6 |
| ||||||||||||||
mariadb-5.5 |
|
Common Weakness Enumeration
References