MariaDB Unspecified Vulnerability

Bug #1899439 reported by Alexander Siahaan
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mariadb-10.1 (Ubuntu)
New
Undecided
Unassigned

Bug Description

Summary

Software

MariaDB 10.1.x, MariaDB 10.2.x, MariaDB 10.3.x, MariaDB 10.4.x

ThreatCon

3 (8 weeks)

CVSS Score

5.6

Due Date*

3 December 2020, 05:50 UTC

Impact

Unknown

Solution Status

Vendor Patched

Attack Vector

From remote

CVE Numbers

CVE‑2020‑15180 <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15180>

*If a patch is currently not available (anymore), the due date applies from the date and time the patch gets available.

Description

A vulnerability with an unknown impact has been reported in MariaDB.

1

An unspecified error exists. No further information is available.

The vulnerability is reported in versions prior to 10.4.15, prior to 10.3.25, prior to 10.2.34, and prior to 10.1.47.

Affected Software

The following software is affected by the described vulnerability. Please check the vendor links below to see if exactly your version is affected.

    MariaDB 10.1.x
    MariaDB 10.2.x
    MariaDB 10.3.x
    MariaDB 10.4.x

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

tags: added: community-security
information type: Private Security → Public Security
Revision history for this message
Daniel Black (daniel-black) wrote :

10.1.48 is now in bionic and this can be closed.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.