Alpine: mariadb: security update to 10.3.27-r0

high Tenable Self-Hosted Container Security Plugin ID 405521

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions
that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable
vulnerability allows low privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of MySQL Server. (CVE-2020-14765)

- Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are
affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable
crash (complete DOS) of MySQL Server. (CVE-2020-14776)

- Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions
that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high
privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful
attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable
crash (complete DOS) of MySQL Server. (CVE-2020-14789)

- Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Locking). Supported versions
that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable
vulnerability allows high privileged attacker with network access via multiple protocols to compromise
MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of MySQL Server. (CVE-2020-14812)

- With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible
for an unprivileged user with an ability to run code on the server machine to intercept the named pipe
connection and act as a man-in-the-middle, gaining access to all the data passed between the client and
the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs
because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before
10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists
because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants
against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other
vendors that were originally affected by CVE-2019-2503. (CVE-2020-28912)

See Also

https://security.alpinelinux.org/vuln/CVE-2020-14765

https://security.alpinelinux.org/vuln/CVE-2020-14776

https://security.alpinelinux.org/vuln/CVE-2020-14789

https://security.alpinelinux.org/vuln/CVE-2020-14812

https://security.alpinelinux.org/vuln/CVE-2020-28912

Plugin Details

Severity: High

ID: 405521

Version: Revision 1.24

Type: Local

Published: 10/31/2023

Updated: 3/12/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.67

CVSS v2

Risk Factor: Medium

Base Score: 4.4

Temporal Score: 3.3

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-28912

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/20/2020

Reference Information

CVE: CVE-2020-14765, CVE-2020-14776, CVE-2020-14789, CVE-2020-14812, CVE-2020-28912