Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.GENTOO.ANNOUNCE
  • [gentoo-announce] [ GLSA 202405-25 ] MariaDB: Multiple Vulnerabilities

    From glsamaker@gentoo.org@21:1/5 to All on Wed May 8 10:50:01 2024
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202405-25
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
    Title: MariaDB: Multiple Vulnerabilities
    Date: May 08, 2024
    Bugs: #699874, #822759, #832490, #838244, #847526, #856484, #891781
    ID: 202405-25

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Multiple vulnerabilities have been discovered in MariaDB, the worst fo
    which can lead to arbitrary execution of code.

    Background
    ==========

    MariaDB is an enhanced, drop-in replacement for MySQL.

    Affected packages
    =================

    Package Vulnerable Unaffected
    -------------- --------------- ----------------
    dev-db/mariadb < 10.11.3:10.11 >= 10.11.3:10.11
    < 10.11.3:10.6 >= 10.6.13:10.6
    < 10.11.3 >= 10.6.13

    Description
    ===========

    Multiple vulnerabilities have been discovered in MariaDB. Please review
    the CVE identifiers referenced below for details.

    Impact
    ======

    Please review the referenced CVE identifiers for details.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All MariaDB 10.6 users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.11.3:10.6"

    All MariaDB 10.11 users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.11.3:10.11"

    References
    ==========

    [ 1 ] CVE-2019-2938
    https://nvd.nist.gov/vuln/detail/CVE-2019-2938
    [ 2 ] CVE-2019-2974
    https://nvd.nist.gov/vuln/detail/CVE-2019-2974
    [ 3 ] CVE-2021-46661
    https://nvd.nist.gov/vuln/detail/CVE-2021-46661
    [ 4 ] CVE-2021-46662
    https://nvd.nist.gov/vuln/detail/CVE-2021-46662
    [ 5 ] CVE-2021-46663
    https://nvd.nist.gov/vuln/detail/CVE-2021-46663
    [ 6 ] CVE-2021-46664
    https://nvd.nist.gov/vuln/detail/CVE-2021-46664
    [ 7 ] CVE-2021-46665
    https://nvd.nist.gov/vuln/detail/CVE-2021-46665
    [ 8 ] CVE-2021-46666
    https://nvd.nist.gov/vuln/detail/CVE-2021-46666
    [ 9 ] CVE-2021-46667
    https://nvd.nist.gov/vuln/detail/CVE-2021-46667
    [ 10 ] CVE-2021-46668
    https://nvd.nist.gov/vuln/detail/CVE-2021-46668
    [ 11 ] CVE-2021-46669
    https://nvd.nist.gov/vuln/detail/CVE-2021-46669
    [ 12 ] CVE-2022-24048
    https://nvd.nist.gov/vuln/detail/CVE-2022-24048
    [ 13 ] CVE-2022-24050
    https://nvd.nist.gov/vuln/detail/CVE-2022-24050
    [ 14 ] CVE-2022-24051
    https://nvd.nist.gov/vuln/detail/CVE-2022-24051
    [ 15 ] CVE-2022-24052
    https://nvd.nist.gov/vuln/detail/CVE-2022-24052
    [ 16 ] CVE-2022-27376
    https://nvd.nist.gov/vuln/detail/CVE-2022-27376
    [ 17 ] CVE-2022-27377
    https://nvd.nist.gov/vuln/detail/CVE-2022-27377
    [ 18 ] CVE-2022-27378
    https://nvd.nist.gov/vuln/detail/CVE-2022-27378
    [ 19 ] CVE-2022-27379
    https://nvd.nist.gov/vuln/detail/CVE-2022-27379
    [ 20 ] CVE-2022-27380
    https://nvd.nist.gov/vuln/detail/CVE-2022-27380
    [ 21 ] CVE-2022-27381
    https://nvd.nist.gov/vuln/detail/CVE-2022-27381
    [ 22 ] CVE-2022-27382
    https://nvd.nist.gov/vuln/detail/CVE-2022-27382
    [ 23 ] CVE-2022-27383
    https://nvd.nist.gov/vuln/detail/CVE-2022-27383
    [ 24 ] CVE-2022-27384
    https://nvd.nist.gov/vuln/detail/CVE-2022-27384
    [ 25 ] CVE-2022-27385
    https://nvd.nist.gov/vuln/detail/CVE-2022-27385
    [ 26 ] CVE-2022-27386
    https://nvd.nist.gov/vuln/detail/CVE-2022-27386
    [ 27 ] CVE-2022-27444
    https://nvd.nist.gov/vuln/detail/CVE-2022-27444
    [ 28 ] CVE-2022-27445
    https://nvd.nist.gov/vuln/detail/CVE-2022-27445
    [ 29 ] CVE-2022-27446
    https://nvd.nist.gov/vuln/detail/CVE-2022-27446
    [ 30 ] CVE-2022-27447
    https://nvd.nist.gov/vuln/detail/CVE-2022-27447
    [ 31 ] CVE-2022-27448
    https://nvd.nist.gov/vuln/detail/CVE-2022-27448
    [ 32 ] CVE-2022-27449
    https://nvd.nist.gov/vuln/detail/CVE-2022-27449
    [ 33 ] CVE-2022-27451
    https://nvd.nist.gov/vuln/detail/CVE-2022-27451
    [ 34 ] CVE-2022-27452
    https://nvd.nist.gov/vuln/detail/CVE-2022-27452
    [ 35 ] CVE-2022-27455
    https://nvd.nist.gov/vuln/detail/CVE-2022-27455
    [ 36 ] CVE-2022-27456
    https://nvd.nist.gov/vuln/detail/CVE-2022-27456
    [ 37 ] CVE-2022-27457
    https://nvd.nist.gov/vuln/detail/CVE-2022-27457
    [ 38 ] CVE-2022-27458
    https://nvd.nist.gov/vuln/detail/CVE-2022-27458
    [ 39 ] CVE-2022-31621
    https://nvd.nist.gov/vuln/detail/CVE-2022-31621
    [ 40 ] CVE-2022-31622
    https://nvd.nist.gov/vuln/detail/CVE-2022-31622
    [ 41 ] CVE-2022-31623
    https://nvd.nist.gov/vuln/detail/CVE-2022-31623
    [ 42 ] CVE-2022-31624
    https://nvd.nist.gov/vuln/detail/CVE-2022-31624
    [ 43 ] CVE-2022-32081
    https://nvd.nist.gov/vuln/detail/CVE-2022-32081
    [ 44 ] CVE-2022-32082
    https://nvd.nist.gov/vuln/detail/CVE-2022-32082
    [ 45 ] CVE-2022-32083
    https://nvd.nist.gov/vuln/detail/CVE-2022-32083
    [ 46 ] CVE-2022-32084
    https://nvd.nist.gov/vuln/detail/CVE-2022-32084
    [ 47 ] CVE-2022-32085
    https://nvd.nist.gov/vuln/detail/CVE-2022-32085
    [ 48 ] CVE-2022-32086
    https://nvd.nist.gov/vuln/detail/CVE-2022-32086
    [ 49 ] CVE-2022-32088
    https://nvd.nist.gov/vuln/detail/CVE-2022-32088
    [ 50 ] CVE-2022-32089
    https://nvd.nist.gov/vuln/detail/CVE-2022-32089
    [ 51 ] CVE-2022-32091
    https://nvd.nist.gov/vuln/detail/CVE-2022-32091
    [ 52 ] CVE-2022-38791
    https://nvd.nist.gov/vuln/detail/CVE-2022-38791
    [ 53 ] CVE-2022-47015
    https://nvd.nist.gov/vuln/detail/CVE-2022-47015
    [ 54 ] CVE-2023-5157
    https://nvd.nist.gov/vuln/detail/CVE-2023-5157

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202405-25

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2024 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmY7OpsACgkQFMQkOaVy +9nENg/9FQV8SNXuIKv8F+DN+CdBIvQ76MlkzXOYcWedQFF8hYcC7gKSnGgFXws0 KTg82DazpW55rYMYAlhLMxUJnerZSl8vB1t59ibDz6QbxPGgig7/fVGUGPJw6O3v RiiZAhvYWVStXm1tmnnRZfNND0efu8flAB3y0fCHnFhKW6RbrIAc/DFsH0bDDar6 WYuLG+ydeGias5N+C353rZV43TUwmvVjk5LSKAi5/7PloW/cbk+gOvy63qxFdLSq jGynX4LwqTBZ1J+Xk0UkTTNTIiI0aRzb2X4L8wz3OGixYC1T+n+iozfcNFokBfW2 warA6C/9ijajk0V+EY35okN5U2m2Uy1QGzACvtSwsXATCqzsWrext9YDJb0ncIMH Un38Fa9ye6mlJsK1Q4e0LS4JFu9Z1YqragW3tIalSqbyyX4T9L7DoFJnKhU+E3Rb wbrAwDdtN4Uf0lXq7uGQBCyopFarUv+vhsAPzWOACuYAocy9lf+YKeJHmz+gmmOb gswaUrcRZLHN3O6Ca+i+bIAtq85VpxKMNqjcy5ss9xhh6QLRyb8hi/ES2HeDOOWh fWLPNhNelwdmXVUCHrkyE364++kbuP1W+EG1LTRDe8eP0fEK0IoBL7AgE+w34KyH vfGW4cPW5mAaGztEgD26qA4fOVq9XuJDGwOKgaFH95Z6BVbAZF0=
    =bHuL
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Gretchiie
      Wed Sep 17 08:54:03 2025
      from Derry, Nh via Telnet
    • Bob Worm
      Wed Sep 17 08:43:18 2025
      from Wales, Uk via Telnet
    • Bob Worm
      Wed Sep 17 08:14:37 2025
      from Wales, Uk via Telnet
    • Volatile_Memory
      Wed Sep 17 07:20:57 2025
      from Des Moines, Iowa via SSH
    • Volatile_Memory
      Wed Sep 17 07:17:26 2025
      from Des Moines, Iowa via SSH
    • Bob Worm
      Tue Sep 16 21:01:27 2025
      from Wales, Uk via Telnet
    • Bob Worm
      Tue Sep 16 15:15:42 2025
      from Wales, Uk via Telnet
    • Gretchiie
      Tue Sep 16 05:20:21 2025
      from Derry, Nh via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 546
    Nodes: 16 (2 / 14)
    Uptime: 58:34:19
    Calls: 10,397
    Calls today: 5
    Files: 14,067
    Messages: 6,417,461
    Posted today: 1

© >>> Magnum BBS <<<, 2025