CVE-2020-13249: High severity mariadb connector/c vulnerability
Last updated 24 July 2024
Other sources
libmariadb/mariadblib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a client. NOTE: although mariadblib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.
Upstream fix:
https://github.com/mariadb-corporation/mariadb-connector-c/commit/2759b87d72926b7c9b5426437a7c8dd15ff57945 https://github.com/mariadb-corporation/mariadb-connector-c/compare/v3.1.7...v3.1.8
— Red Hat
libmariadb/mariadblib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadblib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-13249?
CVE-2020-13249 is a vulnerability in MariaDB Connector/C before 3.1.8 that allows attackers to send malicious OK packets to the server due to improper content validation.
How severe is CVE-2020-13249?
CVE-2020-13249 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2020-13249?
MariaDB Connector/C before 3.1.8, MariaDB 10.4.13, MariaDB 10.3.23, MariaDB 10.2.32, Mariadb Connector/C 3.1.8, openSUSE Leap 15.1, Fedoraproject Fedora 31, Fedoraproject Fedora 32, mariadb-10.3 (debian), mariadb-10.1 (ubuntu), mariadb-10.3 (ubuntu)
How can I fix CVE-2020-13249?
To fix CVE-2020-13249, upgrade to MariaDB Connector/C version 3.1.8 or later.
Where can I find more information about CVE-2020-13249?
You can find more information about CVE-2020-13249 in the references section.