Buffer overflow in MariaDB Connector/C - CVE-2020-13249

 

Buffer overflow in MariaDB Connector/C - CVE-2020-13249

Published: July 1, 2020


Vulnerability identifier: #VU29426
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13249
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of the content of an OK packet received from a server within the libmariadb/mariadb_lib.c file in MariaDB Connector/C.  A remote attacker can trick the victim to connect to a malicious MariaDB server and trigger memory corruption.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

MariaDB Connector/C
mariadb-connector-c (Alpine package)
squid (Alpine package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rh-mariadb102-mariadb (Red Hat package)
rh-mariadb102-galera (Red Hat package)
mariadb-connector-c
mariadb-connector-c-devel
mariadb-connector-c-config
mariadb-connector-c (Red Hat package)
mariadb-server (Ubuntu package)
mariadb
rh-mariadb103-mariadb (Red Hat package)
rh-mariadb103-galera (Red Hat package)
galera
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Opensuse
Ubuntu
Fedora

How to mitigate CVE-2020-13249

Install updates from vendor's website.

MariaDB Connector/C - update to 3.1.8
mariadb-connector-c (Alpine package) - addressed in versions 3.0.8-r1, 3.0.10-r1, 3.1.6-r1
rh-mariadb102-mariadb (Red Hat package) - addressed in versions 10.2.33-1.el6, 10.2.33-1.el7
rh-mariadb102-galera (Red Hat package) - addressed in versions 25.3.29-1.el6, 25.3.29-1.el7
mariadb-connector-c - addressed in versions 3.1.8-1.fc32, 3.1.11-1.fc31
mariadb-connector-c-devel - update to 3.1.11-2
mariadb-connector-c-config - update to 3.1.11-2
mariadb-connector-c - update to 3.1.11-2
mariadb-connector-c (Red Hat package) - addressed in versions 3.1.11-2.el8_0, 3.1.11-2.el8_1, 3.1.11-2.el8_2, 3.1.11-2.el8_3
mariadb-server (Ubuntu package) - addressed in versions 1:10.1.47-0ubuntu0.18.04.1, 1:10.3.25-0ubuntu0.20.04.1
mariadb - addressed in versions 10.3.25-1.fc31, 10.3.26-1.fc31, 10.3-3120201026103040.f636be4b, 10.3-3220201026103040.43bbeeef, 10.4.13-1.fc32, 10.4-3120200608100001.f636be4b, 10.4-3220200608100001.43bbeeef
rh-mariadb103-mariadb (Red Hat package) - update to 10.3.27-1.el7
rh-mariadb103-galera (Red Hat package) - update to 25.3.31-1.el7
galera - addressed in versions 25.3.31-1.fc31, 26.4.4-2.fc32

External References

Related Security Bulletins