漏洞信息详情
MariaDB 安全漏洞
漏洞简介
MariaDB是MariaDB(Mariadb)基金会的一套免费开源的数据库管理系统,也是一个采用Maria存储引擎的MySQL分支版本。
MariaDB存在安全漏洞,该漏洞允许攻击者通过MariaDB的SST非法字符来绕过限制,以提升其特权。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://mariadb.com/kb/en/security/
参考网址
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/10/msg00021.html
来源:GENTOO
链接:https://security.gentoo.org/glsa/202011-14
来源:MISC
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1894919
来源:CONFIRM
链接:https://www.percona.com/blog/2020/10/30/cve-2020-15180-affects-percona-xtradb-cluster/
来源:DEBIAN
链接:https://www.debian.org/security/2020/dsa-4776
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160409/Red-Hat-Security-Advisory-2020-5379-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3633/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4182/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160017/Gentoo-Linux-Security-Advisory-202011-14.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160527/Red-Hat-Security-Advisory-2020-5500-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160273/Red-Hat-Security-Advisory-2020-5246-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4330/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4309/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4427/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4527/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4238/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/MariaDB-privilege-escalation-via-SST-Illegal-Character-33506
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160667/Red-Hat-Security-Advisory-2020-5654-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3698/
受影响实体
暂无
补丁
- MariaDB 安全漏洞的修复措施<!--2020-10-8-->
还没有评论,来说两句吧...