-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2020.3698
USN-4603-1: MariaDB vulnerabilities
28 October 2020
===========================================================================
AusCERT Security Bulletin Summary
---------------------------------
Product: MariaDB
Publisher: Ubuntu
Operating System: Ubuntu
Impact/Access: Execute Arbitrary Code/Commands -- Existing Account
Denial of Service -- Remote with User Interaction
Resolution: Patch/Upgrade
CVE Names: CVE-2020-15180 CVE-2020-13249 CVE-2020-2814
CVE-2020-2812 CVE-2020-2760 CVE-2020-2752
Reference: ASB-2020.0087
ESB-2020.3632
ESB-2020.3450
Original Bulletin:
https://usn.ubuntu.com/4603-1/
- --------------------------BEGIN INCLUDED TEXT--------------------
USN-4603-1: MariaDB vulnerabilities
27 October 2020
Several security issues were fixed in MariaDB.
Releases
o Ubuntu 20.04 LTS
o Ubuntu 18.04 LTS
Packages
o mariadb-10.1 - MariaDB database
o mariadb-10.3 - MariaDB database
Details
It was discovered that MariaDB didn't properly validate the content of a packet
received from a server. A remote attacker could use this vulnerability to sent
a specialy crafted file to cause a denial of service. (CVE-2020-13249)
It was discovered that MariaDB has other security issues. An attacker can cause
a hang or frequently repeatable crash (denial of service). (CVE-2020-15180,
CVE-2020-2752, CVE-2020-2760, CVE-2020-2812, CVE-2020-2814)
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Update instructions
The problem can be corrected by updating your system to the following package
versions:
Ubuntu 20.04
o mariadb-server - 1:10.3.25-0ubuntu0.20.04.1
Ubuntu 18.04
o mariadb-server - 1:10.1.47-0ubuntu0.18.04.1
This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart MariaDB to
make all the necessary changes.
References
o CVE-2020-2760
o CVE-2020-13249
o CVE-2020-2752
o CVE-2020-15180
o CVE-2020-2814
o CVE-2020-2812
Related notices
o USN-4350-1 : mysql-server-5.7, mysql-8.0, mysql-server-8.0, mysql-5.7
- --------------------------END INCLUDED TEXT--------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members. As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release of the security bulletin. It may
not be updated when updates to the original are made. If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.
Contact information for the authors of the original document is included
in the Security Bulletin above. If you have any questions or need further
information, please contact them directly.
Previous advisories and external security bulletins can be retrieved from:
https://www.auscert.org.au/bulletins/
===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072
Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967
iQIVAwUBX5jFreNLKJtyKPYoAQgb8w//QKrEBcserbuBEUQi64FNSkqgx9fMfaTV
zrNGxcd3KRwOGkTQGQB0N/1j4EdvmUufDnJPDeMjmtjhvpgpEN/+U/iQyttLvPav
mwxrsIvfqsHSUEvxvv3Qy+OID7DJExb90Wlk1NkX/tUB2HYaC2TSflS7m3muNP60
NOr4dHHaDDB1iDIxPZidG5uoZQ6t7lf1WH22G7jtHskRVuvDAyvAXmHfTDpE2YvU
ZjWrnwu1iI9lqKfkr1OXNEIRIgSKXO674ZgR1e0qVbFW2C/wM+zUvsVn42xTsioy
F8O/KJuvuHdasUVEDQSqDCX9M5afk2kecTp/OyP7sIoIz5skePA7jKWt8XhPRlWg
P2ePpVy+VfmmtuLafp7tCOddnZ4B1Ij3UVg1uRh2k432CJDR3vOHXBdPBrrT03VJ
PlPhXQ1PFjQOj1OZZ4gRqrn465IGwzQpgcIHnSd58mYtFtCETo+FFcmIYmRODnFO
Zhxewh3eAcoipoyIuX0hJQXQ9aOhKz6Wkwr1+eDTveOxS7m91fX2YJJhbndGwNrq
hxhRboauMOvO0lNXidM3LS333sACcSDx5BrmfSIkwbXj8udy3lEKqmiAMshH6z9c
V5HummxrPpP0VPL+aZaUWxkvghkzyZBSrNFoVSei4XQv9F/zhqZKqbOqz2aN6TT7
giExnWNAQOk=
=QkXL
-----END PGP SIGNATURE-----
The post ESB-2020.3698 – [Ubuntu] MariaDB: Multiple vulnerabilities appeared first on Malware Devil.
https://malwaredevil.com/2020/10/28/esb-2020-3698-ubuntu-mariadb-multiple-vulnerabilities/?utm_source=rss&utm_medium=rss&utm_campaign=esb-2020-3698-ubuntu-mariadb-multiple-vulnerabilities
No comments:
Post a Comment