CVE-2023-26785: Code Injection
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26785?
CVE-2023-26785 is classified as a remote code execution (RCE) vulnerability, which can lead to significant security risks.
How do I fix CVE-2023-26785?
To mitigate CVE-2023-26785, it is advised to upgrade to the latest version of MariaDB that addresses this vulnerability.
Who is affected by CVE-2023-26785?
CVE-2023-26785 affects users of MariaDB v10.5 due to the specific vulnerability in UDF Code.
Can CVE-2023-26785 be exploited remotely?
Yes, CVE-2023-26785 can be exploited remotely due to its nature as a remote code execution vulnerability.
Is there any counterargument regarding CVE-2023-26785?
Yes, the MariaDB Foundation disputes the vulnerability's impact, claiming no privilege boundary is crossed.