MGASA-2022-0314
Dashboard / Vulnerabilities / MGASA-2022-0314
MGASA-2022-0314
Summary: Updated mariadb packages fix security vulnerability
Details: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. (CVE-2018-25032) A use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc. (CVE-2022-32081) An assertion failure at table->get_ref_count() == 0 in dict0dict.cc. (CVE-2022-32082) Segmentation fault via the component sub_select. (CVE-2022-32084) Segmentation fault via the component st_select_lex_unit::exclude_level. (CVE-2022-32089)
References: https://advisories.mageia.org/MGASA-2022-0314.html, https://bugs.mageia.org/show_bug.cgi?id=30754, https://mariadb.com/kb/en/mariadb-10517-release-notes/
Affected packages
Package
Name: mariadb
Purl: pkg:rpm/mageia/mariadb?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
