PT-2022-2345 · Mariadb+10 · Mariadb Server+10
Yaoguang
·
Published
2021-04-01
·
Updated
2025-06-10
·
CVE-2022-27387
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MariaDB Server versions 10.7 and below
Description
The issue is related to a global buffer overflow in the decimal bin size component of the MariaDB Server system. This can be exploited by a remote attacker using specially crafted SQL statements, potentially leading to a denial of service.
Recommendations
For MariaDB Server versions 10.7 and below, consider updating to a version that includes the fix for this issue, as mentioned in the release notes. As a temporary workaround, restrict the use of specially crafted SQL statements to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Mariadb Server
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu