Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2019.0224
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2019-0224)
Resumen:The remote host is missing an update for the 'mariadb' package(s) announced via the MGASA-2019-0224 advisory.
Descripción:Summary:
The remote host is missing an update for the 'mariadb' package(s) announced via the MGASA-2019-0224 advisory.

Vulnerability Insight:
Updated mariadb packages fix security vulnerabilities:

An easily exploitable vulnerability allows high privileged attacker with
network access via multiple protocols to compromise mariadb server.
Successful attacks of this vulnerability can result in unauthorized
ability to cause a hang or frequently repeatable crash (complete DOS)
(CVE-2019-2737).

An easily exploitable vulnerability allows high privileged attacker with
logon to the infrastructure where mariadb server executes to compromise
mariadb server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash
(complete DOS) of mariadb server as well as unauthorized update, insert
or delete access to some of mariadb server accessible data (CVE-2019-2739).

An easily exploitable vulnerability allows low privileged attacker with
network access via multiple protocols to compromise mariadb server.
Successful attacks of this vulnerability can result in unauthorized ability
to cause a hang or frequently repeatable crash (complete DOS) of mariadb
server (CVE-2019-2740).

An easily exploitable vulnerability allows high privileged attacker with
network access via multiple protocols to compromise mariadb server.
Successful attacks of this vulnerability can result in unauthorized ability
to cause a hang or frequently repeatable crash (complete DOS) of mariadb
server as well as unauthorized update, insert or delete access to some of
mariadb server accessible data (CVE-2019-2758).

An easily exploitable vulnerability allows low privileged attacker with
network access via multiple protocols to compromise mariadb server.
Successful attacks of this vulnerability can result in unauthorized ability
to cause a hang or frequently repeatable crash (complete DOS) of mariadb
server (CVE-2019-2805).

This update also fixes issues with FULLTEXT INDEX, Encrypted temporary
tables, Indexed virtual columns, Recovery & Mariabackup.

Affected Software/OS:
'mariadb' package(s) on Mageia 6, Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2019-2737
Bugtraq: 20190802 [slackware-security] mariadb (SSA:2019-213-01) (Google Search)
https://seclists.org/bugtraq/2019/Aug/1
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A55N3HZ3JZBXHQMGTUHY63FVTDU5ILEV/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CN3JPT5ICOAWQNPFVPVLLYR4TQIX4MXP/
http://packetstormsecurity.com/files/153862/Slackware-Security-Advisory-mariadb-Updates.html
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
RedHat Security Advisories: RHSA-2019:2484
https://access.redhat.com/errata/RHSA-2019:2484
RedHat Security Advisories: RHSA-2019:2511
https://access.redhat.com/errata/RHSA-2019:2511
RedHat Security Advisories: RHSA-2019:3708
https://access.redhat.com/errata/RHSA-2019:3708
SuSE Security Announcement: openSUSE-SU-2019:2698 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00037.html
https://usn.ubuntu.com/4070-1/
https://usn.ubuntu.com/4070-2/
https://usn.ubuntu.com/4070-3/
Common Vulnerability Exposure (CVE) ID: CVE-2019-2739
Common Vulnerability Exposure (CVE) ID: CVE-2019-2740
Common Vulnerability Exposure (CVE) ID: CVE-2019-2758
Common Vulnerability Exposure (CVE) ID: CVE-2019-2805
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.