First published: Tue Feb 01 2022(Updated: )
MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mariadb Mariadb | >=10.3.0<10.3.32 | |
Mariadb Mariadb | >=10.4.0<10.4.22 | |
Mariadb Mariadb | >=10.5.0<10.5.13 | |
Mariadb Mariadb | >=10.6.0<10.6.5 | |
redhat/mariadb | <10.3.32 | 10.3.32 |
redhat/mariadb | <10.4.22 | 10.4.22 |
redhat/mariadb | <10.5.13 | 10.5.13 |
redhat/mariadb | <10.6.5 | 10.6.5 |
redhat/mariadb | <10.8.1 | 10.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-46662.
The severity of CVE-2021-46662 is medium.
The versions of MariaDB affected by CVE-2021-46662 are 10.3.0 through 10.3.32, 10.4.0 through 10.4.22, 10.5.0 through 10.5.13, and 10.6.0 through 10.6.5.
CVE-2021-46662 can be exploited by certain uses of an UPDATE statement in conjunction with a nested subquery.
Yes, a fix is available for CVE-2021-46662. Users should update their MariaDB installations to versions 10.3.32, 10.4.22, 10.5.13, or 10.6.5.