Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2019.0224
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2019-0224)
Summary:The remote host is missing an update for the 'mariadb' package(s) announced via the MGASA-2019-0224 advisory.
Description:Summary:
The remote host is missing an update for the 'mariadb' package(s) announced via the MGASA-2019-0224 advisory.

Vulnerability Insight:
Updated mariadb packages fix security vulnerabilities:

An easily exploitable vulnerability allows high privileged attacker with
network access via multiple protocols to compromise mariadb server.
Successful attacks of this vulnerability can result in unauthorized
ability to cause a hang or frequently repeatable crash (complete DOS)
(CVE-2019-2737).

An easily exploitable vulnerability allows high privileged attacker with
logon to the infrastructure where mariadb server executes to compromise
mariadb server. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash
(complete DOS) of mariadb server as well as unauthorized update, insert
or delete access to some of mariadb server accessible data (CVE-2019-2739).

An easily exploitable vulnerability allows low privileged attacker with
network access via multiple protocols to compromise mariadb server.
Successful attacks of this vulnerability can result in unauthorized ability
to cause a hang or frequently repeatable crash (complete DOS) of mariadb
server (CVE-2019-2740).

An easily exploitable vulnerability allows high privileged attacker with
network access via multiple protocols to compromise mariadb server.
Successful attacks of this vulnerability can result in unauthorized ability
to cause a hang or frequently repeatable crash (complete DOS) of mariadb
server as well as unauthorized update, insert or delete access to some of
mariadb server accessible data (CVE-2019-2758).

An easily exploitable vulnerability allows low privileged attacker with
network access via multiple protocols to compromise mariadb server.
Successful attacks of this vulnerability can result in unauthorized ability
to cause a hang or frequently repeatable crash (complete DOS) of mariadb
server (CVE-2019-2805).

This update also fixes issues with FULLTEXT INDEX, Encrypted temporary
tables, Indexed virtual columns, Recovery & Mariabackup.

Affected Software/OS:
'mariadb' package(s) on Mageia 6, Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-2737
Bugtraq: 20190802 [slackware-security] mariadb (SSA:2019-213-01) (Google Search)
https://seclists.org/bugtraq/2019/Aug/1
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A55N3HZ3JZBXHQMGTUHY63FVTDU5ILEV/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CN3JPT5ICOAWQNPFVPVLLYR4TQIX4MXP/
http://packetstormsecurity.com/files/153862/Slackware-Security-Advisory-mariadb-Updates.html
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
RedHat Security Advisories: RHSA-2019:2484
https://access.redhat.com/errata/RHSA-2019:2484
RedHat Security Advisories: RHSA-2019:2511
https://access.redhat.com/errata/RHSA-2019:2511
RedHat Security Advisories: RHSA-2019:3708
https://access.redhat.com/errata/RHSA-2019:3708
SuSE Security Announcement: openSUSE-SU-2019:2698 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00037.html
https://usn.ubuntu.com/4070-1/
https://usn.ubuntu.com/4070-2/
https://usn.ubuntu.com/4070-3/
Common Vulnerability Exposure (CVE) ID: CVE-2019-2739
Common Vulnerability Exposure (CVE) ID: CVE-2019-2740
Common Vulnerability Exposure (CVE) ID: CVE-2019-2758
Common Vulnerability Exposure (CVE) ID: CVE-2019-2805
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.