First published: Tue Feb 01 2022(Updated: )
MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mariadb Mariadb | <10.2.39 | |
Mariadb Mariadb | >=10.3.0<10.3.30 | |
Mariadb Mariadb | >=10.4.0<10.4.20 | |
Mariadb Mariadb | >=10.5.0<10.5.11 | |
Mariadb Mariadb | >=10.6.0<10.6.2 | |
redhat/mariadb | <10.2.39 | 10.2.39 |
redhat/mariadb | <10.3.30 | 10.3.30 |
redhat/mariadb | <10.4.20 | 10.4.20 |
redhat/mariadb | <10.5.11 | 10.5.11 |
redhat/mariadb | <10.6.2 | 10.6.2 |
redhat/mariadb | <10.8.1 | 10.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-46666.
The severity of CVE-2021-46666 is medium.
The affected software for CVE-2021-46666 is MariaDB versions before 10.6.2.
CVE-2021-46666 can be exploited by triggering mishandling of a pushdown from a HAVING clause to a WHERE clause in MariaDB.
Yes, upgrading to MariaDB version 10.6.2 or higher will remediate CVE-2021-46666.