QID 375771

Date Published: 2021-11-11

QID 375771: MariaDB Denial of Service Vulnerabilities

MariaDB is a database server that offers drop-in replacement functionality for MySQL.

Multiple Vulnerabilities exists in MariaDB:
CVE-2021-2389
CVE-2021-2372

Affected Versions:
10.2 before 10.2.40
10.3 before 10.3.31
10.4 before 10.4.21
10.5 before 10.5.12
10.6 before 10.6.4
QID Detection Logic:(Authenticated)
This QID checks for the version of file aria_chk.exe to detect the vulnerable version of MariaDB

Successful exploitation of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as High - 7.1 severity.
  • Solution
    Customers are advised to upgrade to the latest version of software available. The latest version can be downloaded from here

    CVEs related to QID 375771

    Software Advisories
    Advisory ID Software Component Link
    MariaDB Downloads URL Logo downloads.mariadb.org/