=========================================================================== ZMCIRT Vulnerability Bulletin ZMC-2021.12.13.0800 MariaDB: Multiple vulnerabilities 13th December 2021 =========================================================================== Product: MariaDB Publisher: Ubuntu Operating System: Ubuntu Impact/Access: Modify Arbitrary Files -- Existing Account Delete Arbitrary Files -- Existing Account Denial of Service -- Existing Account Access Confidential Data -- Existing Account Reduced Security -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2021-35604 Reference: ESB-2021.4123 ESB-2021.4068 Original Bulletin: https://ubuntu.com/security/notices/USN-5170-1 - --------------------------BEGIN INCLUDED TEXT-------------------- USN-5170-1: MariaDB vulnerability 06 December 2021 A security issue was fixed in MariaDB Releases o Ubuntu 21.10 o Ubuntu 21.04 o Ubuntu 20.04 LTS Packages o mariadb-10.3 - MariaDB database o mariadb-10.5 - MariaDB database Details A security issue was discovered in MariaDB and this update includes new upstream MariaDB versions to fix the issue. MariaDB has been updated to 10.3.32 in Ubuntu 20.04 LTS and to 10.5.13 in Ubuntu 21.04 and Ubuntu 21.10. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10 o mariadb-server - 1:10.5.13-0ubuntu0.21.10.1 Ubuntu 21.04 o mariadb-server - 1:10.5.13-0ubuntu0.21.04.1 Ubuntu 20.04 o mariadb-server - 1:10.3.32-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart MariaDB to make all the necessary changes. References o CVE-2021-35604 Related notices o USN-5123-1 : libmysqld-dev, mysql-client, mysql-server-8.0, mysql-testsuite, libmysqlclient-dev, mysql-5.7, mysql-testsuite-5.7, mysql-client-8.0, mysql-client-core-8.0, mysql-client-core-5.7, libmysqlclient21, mysql-server, libmysqlclient20, mysql-server-5.7, mysql-server-core-8.0, mysql-source-8.0, mysql-client-5.7, mysql-source-5.7, mysql-router, mysql-testsuite-8.0, mysql-8.0, mysql-server-core-5.7 o USN-5123-2 : mysql-testsuite, libmysqlclient-dev, mysql-server, libmysqlclient20, mysql-server-5.7, libmysqld-dev, mysql-5.7, mysql-client, mysql-testsuite-5.7, mysql-source-5.7, mysql-client-5.7, mysql-common, mysql-client-core-5.7, mysql-server-core-5.7 ---------------------------END INCLUDED TEXT-------------------- ZMCIRT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. ZMCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Internet Email: report@cirt.zm Telephone: 7070 ZMCIRT personnel answer during Zambian business hours which are 8am to 5pm. On call after hours for member emergencies only. ===========================================================================
Copyright @2023 ZAMBIA CIRT