CVE-2024-27766: Code Injection
An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the libmysqludfsys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27766?
The severity of CVE-2024-27766 is currently under dispute, as it involves execution of arbitrary code without crossing privilege boundaries.
How do I fix CVE-2024-27766?
To address CVE-2024-27766, ensure your MariaDB version is updated to the latest patch that addresses this vulnerability.
Who is affected by CVE-2024-27766?
CVE-2024-27766 affects users of MariaDB v.11.1, particularly those utilizing the lib_mysqludf_sys.so function.
What impact does CVE-2024-27766 have?
CVE-2024-27766 allows a remote attacker to execute arbitrary code, potentially compromising server integrity.
Is there a workaround for CVE-2024-27766?
Currently, there are no specific workarounds mentioned for CVE-2024-27766, but staying updated can help mitigate risks.