CVE-2022-31026
Summary
| CVE | CVE-2022-31026 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-09 13:15:00 UTC |
| Updated | 2022-06-15 18:26:00 UTC |
| Description | Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authentication packet, causing the client to read and return up to 12 bytes of data from an uninitialized variable in stack memory. Users of the trilogy gem should upgrade to version 2.1.1 This issue can be avoided by only connecting to trusted servers. |
Risk And Classification
Problem Types: CWE-908
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trilogy Project | Trilogy | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Use of Uninitialized Variable in trilogy · Advisory · github/trilogy · GitHub | CONFIRM | github.com | |
| Merge pull request from GHSA-5g4r-2qhx-vqfm · github/trilogy@6bed627 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.