Buffer overflow in MariaDB Connector/C - CVE-2020-13249
Published: July 1, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of the content
of an OK packet received from a server within the
libmariadb/mariadb_lib.c file in MariaDB Connector/C. A remote attacker can trick the victim to connect to a malicious MariaDB server and trigger memory corruption.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
mariadb-connector-c (Alpine package)
squid (Alpine package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rh-mariadb102-mariadb (Red Hat package)
rh-mariadb102-galera (Red Hat package)
mariadb-connector-c
mariadb-connector-c-devel
mariadb-connector-c-config
mariadb-connector-c (Red Hat package)
mariadb-server (Ubuntu package)
mariadb
rh-mariadb103-mariadb (Red Hat package)
rh-mariadb103-galera (Red Hat package)
galera
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Opensuse
Ubuntu
Fedora
How to mitigate CVE-2020-13249
mariadb-connector-c (Alpine package) - addressed in versions 3.0.8-r1, 3.0.10-r1, 3.1.6-r1
rh-mariadb102-mariadb (Red Hat package) - addressed in versions 10.2.33-1.el6, 10.2.33-1.el7
rh-mariadb102-galera (Red Hat package) - addressed in versions 25.3.29-1.el6, 25.3.29-1.el7
mariadb-connector-c - addressed in versions 3.1.8-1.fc32, 3.1.11-1.fc31
mariadb-connector-c-devel - update to 3.1.11-2
mariadb-connector-c-config - update to 3.1.11-2
mariadb-connector-c - update to 3.1.11-2
mariadb-connector-c (Red Hat package) - addressed in versions 3.1.11-2.el8_0, 3.1.11-2.el8_1, 3.1.11-2.el8_2, 3.1.11-2.el8_3
mariadb-server (Ubuntu package) - addressed in versions 1:10.1.47-0ubuntu0.18.04.1, 1:10.3.25-0ubuntu0.20.04.1
mariadb - addressed in versions 10.3.25-1.fc31, 10.3.26-1.fc31, 10.3-3120201026103040.f636be4b, 10.3-3220201026103040.43bbeeef, 10.4.13-1.fc32, 10.4-3120200608100001.f636be4b, 10.4-3220200608100001.43bbeeef
rh-mariadb103-mariadb (Red Hat package) - update to 10.3.27-1.el7
rh-mariadb103-galera (Red Hat package) - update to 25.3.31-1.el7
galera - addressed in versions 25.3.31-1.fc31, 26.4.4-2.fc32
External References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00064.html
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00054.html
- https://github.com/mariadb-corporation/mariadb-connector-c/commit/2759b87d72926b7c9b5426437a7c8dd15ff57945
- https://github.com/mariadb-corporation/mariadb-connector-c/compare/v3.1.7...v3.1.8
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UW2ED32VEUHXFN2J3YQE27JIBV4SC2PI/
Related Security Bulletins
- Memory corruption in MariaDB Connector/C
- OpenSUSE Linux update for mariadb
- OpenSUSE Linux update for mariadb-connector-c
- Red Hat Software Collections update for rh-mariadb102-mariadb and rh-mariadb102-galera
- Red Hat Enterprise Linux 8 update for mariadb-connector-c
- Red Hat Enterprise Linux TUS 8.0 update for the mariadb:10.3 module
- Red Hat Enterprise Linux TUS 8.2 update for mariadb-connector-c
- Red Hat Enterprise Linux 8.1 update for mariadb-connector-c
- Red Hat Enterprise Linux 8 update for mariadb-connector-c
- Red Hat Enterprise Linux 8 update for the mariadb:10.3 module
- Red Hat Enterprise Linux 8.1 update for the mariadb:10.3 module
- Buffer overflow in mariadb-connector-c (Alpine package)
- Red Hat Software Collections update for rh-mariadb103-mariadb and rh-mariadb103-galera
- Anolis OS update for mariadb-connector-c
- Ubuntu update for mariadb-10.1
- Red Hat Enterprise Linux 8 update for the mariadb:10.3 module
- Fedora 32 update for galera, mariadb, mariadb-connector-c
- Fedora 32 Modular update for mariadb
- Fedora 31 Modular update for mariadb
- Fedora 32 Modular update for mariadb
- Fedora 31 update for mariadb
- Fedora 31 Modular update for mariadb
- Fedora 31 update for galera, mariadb, mariadb-connector-c