← Back

CVE-2022-24052

nvd nist
Published: Feb 18, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16190.

Affected (10)

1 product
Mariadb
1 product
Fedora
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Mariadb
From 10.2.0 to 10.2.42
From 10.3.0 to 10.3.33
From 10.4.0 to 10.4.23
From 10.5.0 to 10.5.14
From 10.6.0 to 10.6.6
From 10.7.0 to 10.7.2
Version 10.8.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Version 36

References (12)

Source: zdi-disclosures@trendmicro.com
PatchVendor Advisory
Source: zdi-disclosures@trendmicro.com
Third Party Advisory
Source: zdi-disclosures@trendmicro.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.