#VU29426 Buffer overflow in MariaDB Connector/C - CVE-2020-13249
Published: July 1, 2020
MariaDB Connector/C
MariaDB Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of the content
of an OK packet received from a server within the
libmariadb/mariadb_lib.c file in MariaDB Connector/C. A remote attacker can trick the victim to connect to a malicious MariaDB server and trigger memory corruption.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00064.html
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00054.html
- https://github.com/mariadb-corporation/mariadb-connector-c/commit/2759b87d72926b7c9b5426437a7c8dd15ff57945
- https://github.com/mariadb-corporation/mariadb-connector-c/compare/v3.1.7...v3.1.8
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UW2ED32VEUHXFN2J3YQE27JIBV4SC2PI/