Lucene search

K
rosalinuxROSA LABROSA-SA-2024-2413
HistoryMay 02, 2024 - 9:15 a.m.

Advisory ROSA-SA-2024-2413

2024-05-0209:15:10
ROSA LAB
abf.rosalinux.ru
11
mariadb 10.5.23
rosa-chrome
vulnerability
exploitation
denial of service
fixed
update
command
unix

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

7

Confidence

High

EPSS

0.002

Percentile

57.1%

software: mariadb 10.5.23
AXIS: ROSA-CHROME

package_evr_string: mariadb-10.5.23-1

CVE-ID: CVE-2022-47015
BDU-ID: 2023-03856
CVE-Crit: MEDIUM.
CVE-DESC.: A vulnerability in the spider_db_mbase::print_warnings() function of the MariaDB DBMS is related to pointer dereferencing errors. Exploitation of the vulnerability allows an attacker acting remotely to cause a denial of service
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update mariadb

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchmariadb< 10.5.23UNKNOWN

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

7

Confidence

High

EPSS

0.002

Percentile

57.1%