UBUNTU-CVE-2020-13249
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-13249
UBUNTU-CVE-2020-13249
Summary:
Details: libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.
References: https://ubuntu.com/security/CVE-2020-13249, https://github.com/mariadb-corporation/mariadb-connector-c/commit/2759b87d72926b7c9b5426437a7c8dd15ff57945, https://github.com/mariadb-corporation/mariadb-connector-c/compare/v3.1.7...v3.1.8, https://ubuntu.com/security/notices/USN-4603-1, https://www.cve.org/CVERecord?id=CVE-2020-13249
Affected packages
Package
Name: mariadb-10.0
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
