Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2020-13249

Published: May 20, 2020Last modified: November 8, 2023

Description

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

Severity score breakdown

ParameterValue
Base score8.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSmariadbNot affected (10.6.14-r0)
mariadb-connector-cNot affected (3.3.3-r0)
StreammariadbNot affected (10.11.5-r1)
mariadb-connector-cNot affected (3.3.3-r0)

References

ON THIS PAGE