Revision Date: | 2022-09-02 | Version: | 1 |
Title: | CVE-2022-27377 |
Description: |
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.
|
Family: | unix | Class: | vulnerability |
Status: | | Reference(s): | Mitre CVE-2022-27377 SUSE CVE-2022-27377 SUSE-SU-2022:2003-1 SUSE-SU-2022:2107-1 SUSE-SU-2022:2160-1 SUSE-SU-2022:2189-1 SUSE-SU-2022:2561-1
|
Platform(s): | openSUSE Leap 15.4 SUSE CaaS Platform 4.0 SUSE Enterprise Storage 7 SUSE Linux Enterprise Desktop 12 SP5 SUSE Linux Enterprise High Performance Computing 12 SP5 SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS SUSE Linux Enterprise High Performance Computing 15 SP3 SUSE Linux Enterprise High Performance Computing 15 SP4 SUSE Linux Enterprise Module for Server Applications 15 SP3 SUSE Linux Enterprise Module for Server Applications 15 SP4 SUSE Linux Enterprise Real Time 15 SP2 SUSE Linux Enterprise Server 12 SP4-ESPOS SUSE Linux Enterprise Server 12 SP4-LTSS SUSE Linux Enterprise Server 12 SP5 SUSE Linux Enterprise Server 15 SP2-BCL SUSE Linux Enterprise Server 15 SP2-LTSS SUSE Linux Enterprise Server 15 SP3 SUSE Linux Enterprise Server 15 SP4 SUSE Linux Enterprise Server for SAP Applications 12 SP4 SUSE Linux Enterprise Server for SAP Applications 12 SP5 SUSE Linux Enterprise Server for SAP Applications 15 SP1 SUSE Linux Enterprise Server for SAP Applications 15 SP2 SUSE Linux Enterprise Server for SAP Applications 15 SP3 SUSE Linux Enterprise Server for SAP Applications 15 SP4 SUSE Linux Enterprise Storage 7.1 SUSE Linux Enterprise Workstation Extension 12 SP5 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.1 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.1 SUSE Manager Server 4.2 SUSE Manager Server 4.3 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud Crowbar 9
| Product(s): | |
Definition Synopsis |
Release Information SUSE CaaS Platform 4.0 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
AND Package Information
libmysqld-devel is affected
OR libmysqld19 is affected
OR mariadb is affected
OR mariadb-client is affected
OR mariadb-errormessages is affected
OR mariadb-tools is affected
|
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
AND Package Information
libmysqld-devel is affected
OR libmysqld19 is affected
OR mariadb is affected
OR mariadb-client is affected
OR mariadb-errormessages is affected
OR mariadb-tools is affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Real Time 15 SP2 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
OR SUSE Manager Proxy 4.1 is installed
OR SUSE Manager Retail Branch Server 4.1 is installed
OR SUSE Manager Server 4.1 is installed
AND Package Information
libmariadbd-devel is affected
OR libmariadbd19 is affected
OR mariadb is affected
OR mariadb-client is affected
OR mariadb-errormessages is affected
OR mariadb-tools is affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
OR SUSE Linux Enterprise Module for Server Applications 15 SP3 is installed
OR SUSE Linux Enterprise Server 15 SP3 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
OR SUSE Linux Enterprise Storage 7.1 is installed
OR SUSE Manager Proxy 4.2 is installed
OR SUSE Manager Retail Branch Server 4.2 is installed
OR SUSE Manager Server 4.2 is installed
AND Package Information
libmariadbd-devel is affected
OR libmariadbd19 is affected
OR mariadb is affected
OR mariadb-client is affected
OR mariadb-errormessages is affected
OR mariadb-tools is affected
|
Definition Synopsis |
Release Information
SUSE OpenStack Cloud 8 is installed
OR SUSE OpenStack Cloud Crowbar 8 is installed
AND Package Information
libmysqlclient18 is not affected
OR libmysqlclient18-32bit is not affected
OR mariadb is not affected
OR mariadb-client is not affected
OR mariadb-errormessages is not affected
OR mariadb-galera is not affected
OR mariadb-tools is not affected
|
Definition Synopsis |
Release Information
SUSE OpenStack Cloud 9 is installed
OR SUSE OpenStack Cloud Crowbar 9 is installed
AND Package Information
mariadb is affected
OR mariadb-client is affected
OR mariadb-errormessages is affected
OR mariadb-galera is affected
OR mariadb-tools is affected
OR libmysqlclient18 is not affected
OR libmysqlclient18-32bit is not affected
OR mariadb-100-errormessages is not affected
|
Definition Synopsis |
Release Information
SUSE Enterprise Storage 7 is installed
OR SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
OR SUSE Linux Enterprise Module for Server Applications 15 SP3 is installed
OR SUSE Linux Enterprise Real Time 15 SP2 is installed
OR SUSE Linux Enterprise Server 15 SP3 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
OR SUSE Linux Enterprise Storage 7.1 is installed
OR SUSE Manager Proxy 4.2 is installed
OR SUSE Manager Retail Branch Server 4.2 is installed
OR SUSE Manager Server 4.2 is installed
AND Package Information
libmariadbd-devel is affected
OR libmariadbd19 is affected
OR mariadb is affected
OR mariadb-client is affected
OR mariadb-errormessages is affected
OR mariadb-tools is affected
|
Definition Synopsis |
openSUSE Leap 15.4 is installed
AND Package Information
libmysqld-devel-10.2.44-150000.3.54.1 is installed
AND libmysqld-devel is signed with openSUSE key
OR
libmysqld19-10.2.44-150000.3.54.1 is installed
AND libmysqld19 is signed with openSUSE key
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
OR SUSE Linux Enterprise Module for Server Applications 15 SP4 is installed
OR SUSE Linux Enterprise Server 15 SP4 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
OR SUSE Manager Proxy 4.3 is installed
OR SUSE Manager Retail Branch Server 4.3 is installed
OR SUSE Manager Server 4.3 is installed
AND Package Information
libmariadbd-devel-10.6.8-150400.3.7.1 is installed
OR libmariadbd19-10.6.8-150400.3.7.1 is installed
OR mariadb-10.6.8-150400.3.7.1 is installed
OR mariadb-client-10.6.8-150400.3.7.1 is installed
OR mariadb-errormessages-10.6.8-150400.3.7.1 is installed
OR mariadb-tools-10.6.8-150400.3.7.1 is installed
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
AND mariadb-100 is not affected
OR Package Information
SUSE Linux Enterprise Desktop 12 SP5 is installed
OR SUSE Linux Enterprise Server 12 SP5 is installed
OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
OR SUSE Linux Enterprise Workstation Extension 12 SP5 is installed
AND
libmysqlclient_r18 is not affected
OR libmysqlclient_r18-32bit is not affected
OR Package Information
SUSE Linux Enterprise Server 12 SP5 is installed
AND
mariadb-10.2.44-3.50.1 is installed
OR mariadb-client-10.2.44-3.50.1 is installed
OR mariadb-errormessages-10.2.44-3.50.1 is installed
OR mariadb-tools-10.2.44-3.50.1 is installed
OR libmysqlclient18 is not affected
OR libmysqlclient18-32bit is not affected
OR mariadb-100-errormessages is not affected
OR Package Information
SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
AND
mariadb-10.2.44-3.50.1 is installed
OR mariadb-client-10.2.44-3.50.1 is installed
OR mariadb-errormessages-10.2.44-3.50.1 is installed
OR mariadb-tools-10.2.44-3.50.1 is installed
OR mariadb-100 is not affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS is installed
OR SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS is installed
AND
libmariadbd-devel-10.4.25-150200.3.28.1 is installed
OR libmariadbd19-10.4.25-150200.3.28.1 is installed
OR mariadb-10.4.25-150200.3.28.1 is installed
OR mariadb-client-10.4.25-150200.3.28.1 is installed
OR mariadb-errormessages-10.4.25-150200.3.28.1 is installed
OR mariadb-tools-10.4.25-150200.3.28.1 is installed
OR Package Information
SUSE Linux Enterprise Server 15 SP2-BCL is installed
AND
libmariadbd-devel-10.4.25-150200.3.28.1 is installed
OR libmariadbd19-10.4.25-150200.3.28.1 is installed
OR mariadb-10.4.25-150200.3.28.1 is installed
OR mariadb-client-10.4.25-150200.3.28.1 is installed
OR mariadb-errormessages-10.4.25-150200.3.28.1 is installed
OR mariadb-tools-10.4.25-150200.3.28.1 is installed
OR Package Information
SUSE Linux Enterprise Server 15 SP2-LTSS is installed
AND
libmariadbd-devel-10.4.25-150200.3.28.1 is installed
OR libmariadbd19-10.4.25-150200.3.28.1 is installed
OR mariadb-10.4.25-150200.3.28.1 is installed
OR mariadb-client-10.4.25-150200.3.28.1 is installed
OR mariadb-errormessages-10.4.25-150200.3.28.1 is installed
OR mariadb-tools-10.4.25-150200.3.28.1 is installed
OR Package Information
SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
AND
libmariadbd-devel-10.4.25-150200.3.28.1 is installed
OR libmariadbd19-10.4.25-150200.3.28.1 is installed
OR mariadb-10.4.25-150200.3.28.1 is installed
OR mariadb-client-10.4.25-150200.3.28.1 is installed
OR mariadb-errormessages-10.4.25-150200.3.28.1 is installed
OR mariadb-tools-10.4.25-150200.3.28.1 is installed
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
AND
mariadb-10.2.44-3.50.1 is installed
OR mariadb-client-10.2.44-3.50.1 is installed
OR mariadb-errormessages-10.2.44-3.50.1 is installed
OR mariadb-tools-10.2.44-3.50.1 is installed
OR libmysqlclient18 is not affected
OR libmysqlclient18-32bit is not affected
OR mariadb-100-errormessages is not affected
OR Package Information
SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
AND
mariadb-10.2.44-3.50.1 is installed
OR mariadb-client-10.2.44-3.50.1 is installed
OR mariadb-errormessages-10.2.44-3.50.1 is installed
OR mariadb-tools-10.2.44-3.50.1 is installed
OR Package Information
SUSE Linux Enterprise Server 12 SP4-LTSS is installed
AND
mariadb-10.2.44-3.50.1 is installed
OR mariadb-client-10.2.44-3.50.1 is installed
OR mariadb-errormessages-10.2.44-3.50.1 is installed
OR mariadb-tools-10.2.44-3.50.1 is installed
|