CVE-2022-27380: SQL Injection
An issue in the component mydecimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
CVE-2022-27380
What is the severity level of CVE-2022-27380?
The severity level of CVE-2022-27380 is high (7.5).
What is the affected software for CVE-2022-27380?
The affected software for CVE-2022-27380 includes versions of MariaDB Server up to 10.6.3.
How can attackers exploit CVE-2022-27380?
Attackers can exploit CVE-2022-27380 by using specially crafted SQL statements to cause a Denial of Service (DoS).
Where can I find more information about CVE-2022-27380?
You can find more information about CVE-2022-27380 in the following references: [Reference 1](https://jira.mariadb.org/browse/MDEV-26280), [Reference 2](https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html), [Reference 3](https://security.netapp.com/advisory/ntap-20220526-0007/).