Bastien Roucariès pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
59d00f5d by Bastien Roucariès at 2024-09-17T15:58:33+00:00
CVE-2022-27449/mariadb

Add:
- commit
- main bug

Add fix other CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -198076,7 +198076,13 @@ CVE-2022-27449 (MariaDB Server v10.9 and below was 
discovered to contain a segme
        [bullseye] - mariadb-10.5 1:10.5.18-0+deb11u1
        - mariadb-10.3 <removed>
        - mariadb-10.1 <removed>
-       NOTE: https://jira.mariadb.org/browse/MDEV-28089
+       NOTE: MariaDB bug: https://jira.mariadb.org/browse/MDEV-28089
+       NOTE: MariaDB main bug: https://jira.mariadb.org/browse/MDEV-24176
+       NOTE: Same fix than CVE-2022-27376, CVE-2022-27379, CVE-2022-27447
+       NOTE: Fixed in MariaDB 10.3.35, 10.4.25, 10.5.16, 10.6.8, 10.7.4, 10.8.3
+       NOTE: MariaDB commit: [1/3] 
https://github.com/MariaDB/server/commit/c02ebf3510850ba78a106be9974c94c3b97d8585
 (mariadb-10.3.35)
+       NOTE: MariaDB commit: [2/3] 
https://github.com/MariaDB/server/commit/08c7ab404f69d9c4ca6ca7a9cf7eec74c804f917
 (mariadb-10.3.35)
+       NOTE: MariaDB commit: [3/3] 
https://github.com/MariaDB/server/commit/b3c3291f0b7c1623cb20663f7cf31b7f749768bc
 (mariadb-10.3.35)
 CVE-2022-27448 (There is an Assertion failure in MariaDB Server v10.9 and 
below via 'n ...)
        {DLA-3114-1}
        - mariadb-10.6 1:10.6.8-1
@@ -198096,7 +198102,7 @@ CVE-2022-27447 (MariaDB Server v10.9 and below was 
discovered to contain a use-a
        - mariadb-10.1 <removed>
        NOTE: MariaDB bug: https://jira.mariadb.org/browse/MDEV-28099
        NOTE: MariaDB main bug: https://jira.mariadb.org/browse/MDEV-24176
-       NOTE: Same fix than CVE-2022-27376 and CVE-2022-27379
+       NOTE: Same fix than CVE-2022-27376, CVE-2022-27379 and CVE-2022-27449
        NOTE: Fixed in MariaDB 10.3.35, 10.4.25, 10.5.16, 10.6.8, 10.7.4, 10.8.3
        NOTE: MariaDB commit: [1/3] 
https://github.com/MariaDB/server/commit/c02ebf3510850ba78a106be9974c94c3b97d8585
 (mariadb-10.3.35)
        NOTE: MariaDB commit: [2/3] 
https://github.com/MariaDB/server/commit/08c7ab404f69d9c4ca6ca7a9cf7eec74c804f917
 (mariadb-10.3.35)
@@ -198356,7 +198362,7 @@ CVE-2022-27379 (An issue in the component 
Arg_comparator::compare_real_fixed of
        - mariadb-10.1 <removed>
        NOTE: MariaDB bug: https://jira.mariadb.org/browse/MDEV-26353
        NOTE: MariaDB bug (main): https://jira.mariadb.org/browse/MDEV-24176
-       NOTE: Same fix than CVE-2022-27376 and CVE-2022-27447
+       NOTE: Same fix than CVE-2022-27376, CVE-2022-27447 and CVE-2022-27449
        NOTE: Fixed in MariaDB version 10.3.35, 10.4.25, 10.5.16, 10.6.8, 10.7.4
 CVE-2022-27378 (An issue in the component Create_tmp_table::finalize of 
MariaDB Server ...)
        {DLA-3114-1}
@@ -198388,7 +198394,7 @@ CVE-2022-27376 (MariaDB Server v10.6.5 and below was 
discovered to contain an us
        NOTE: Bug MariaDB: https://jira.mariadb.org/browse/MDEV-26354
        NOTE: Bug MariaDB (duplicate): 
https://jira.mariadb.org/browse/MDEV-26437
        NOTE: Bug MariaDB (main): https://jira.mariadb.org/browse/MDEV-24176
-       NOTE: Same fix than CVE-2022-27379 and CVE-2022-27447
+       NOTE: Same fix than CVE-2022-27379, CVE-2022-27447 and CVE-2022-27449
        NOTE: Fixed in MariaDB version 10.3.35, 10.4.25, 10.5.16, 10.6.8, 10.7.4
        NOTE: Commit MariaDB [1/3] 
https://github.com/MariaDB/server/commit/c02ebf3510850ba78a106be9974c94c3b97d8585
        NOTE: Commit MariaDB [2/3] 
https://github.com/MariaDB/server/commit/08c7ab404f69d9c4ca6ca7a9cf7eec74c804f917



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59d00f5df3b80a96628e6c1288325cf0f66483e9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59d00f5df3b80a96628e6c1288325cf0f66483e9
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to