EulerOS Virtualization 3.0.2.2 : mariadb (EulerOS-SA-2023-1274)

medium Nessus Plugin ID 170845

Synopsis

The remote EulerOS Virtualization host is missing multiple security updates.

Description

According to the versions of the mariadb packages installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerabilities :

- get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY. (CVE-2021-46657)

- MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause. (CVE-2021-46666)

- MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash. (CVE-2021-46667)

- MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock. (CVE-2022-31624)

Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected mariadb packages.

See Also

http://www.nessus.org/u?38b4706c

Plugin Details

Severity: Medium

ID: 170845

File Name: EulerOS_SA-2023-1274.nasl

Version: 1.1

Type: local

Published: 1/30/2023

Updated: 9/5/2023

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2022-31624

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:huawei:euleros:mariadb, p-cpe:/a:huawei:euleros:mariadb-libs, p-cpe:/a:huawei:euleros:mariadb-server, cpe:/o:huawei:euleros:uvp:3.0.2.2

Required KB Items: Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/uvp_version, Host/local_checks_enabled

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/30/2023

Vulnerability Publication Date: 1/29/2022

Reference Information

CVE: CVE-2021-46657, CVE-2021-46666, CVE-2021-46667, CVE-2022-31624