QID 375771
Date Published: 2021-11-11
QID 375771: MariaDB Denial of Service Vulnerabilities
MariaDB is a database server that offers drop-in replacement functionality for MySQL.
Multiple Vulnerabilities exists in MariaDB:
CVE-2021-2389
CVE-2021-2372
Affected Versions:
10.2 before 10.2.40
10.3 before 10.3.31
10.4 before 10.4.21
10.5 before 10.5.12
10.6 before 10.6.4
QID Detection Logic:(Authenticated)
This QID checks for the version of file aria_chk.exe to detect the vulnerable version of MariaDB
Successful exploitation of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash.
Solution
Customers are advised to upgrade to the latest version of software available. The latest version can be downloaded from here
Vendor References
- MariaDB10.2 -
mariadb.com/kb/en/mdb-10240-rn/ - MariaDB10.3 -
mariadb.com/kb/en/mdb-10331-rn/ - MariaDB10.4 -
mariadb.com/kb/en/mdb-10421-rn/ - MariaDB10.5 -
mariadb.com/kb/en/mdb-10512-rn/ - MariaDB10.6 -
mariadb.com/kb/es/mariadb-1064-release-notes/
CVEs related to QID 375771
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| MariaDB Downloads |
|