← Back

CVE-2022-27383

nvd nist
Published: Apr 12, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

Affected (8)

1 product
Mariadb
1 product
Debian Linux
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Mariadb
From 10.2.0 to 10.2.44
From 10.3.0 to 10.3.35
From 10.4.0 to 10.4.25
From 10.5.0 to 10.5.16
From 10.6.0 to 10.6.8
From 10.7.0 to 10.7.4
From 10.8.0 to 10.8.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (6)

Source: cve@mitre.org
ExploitIssue TrackingVendor Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.