Release date:
Updated on:
Affected Systems:
MariaDB <5.5.36
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65757
MariaDB is a MySQL branch version that uses the Maria storage engine.
MariaDB versions earlier than 5.5.36 have multiple implementation vulnerabilities, which can cause DoS attacks to malicious users.
1. An indirect NULL pointer reference error may occur when you process the prepared SELECT statement for some queries, which may cause a crash. To use this vulnerability successfully, you need to enable the "materialization" and "semijoin" optimizer.
2. An error occurred while processing kill query statements with some concurrent SQL queries, which may cause a crash;
3. An error occurred while parsing the NAME_CONST expression containing the AND/OR expression, which may cause a crash;
4. An error occurs when preparing a SELECT statement with an invalid group by value. An asserted error can be triggered;
5. If an error occurs when processing some SELECT statements with JOIN resolution, a crash may occur. To use this vulnerability successfully, you must set "SQL _mode" to "ONLY_FULL_GROUP_BY ".
6. An error occurs when processing some concurrent UPDATE statements, which can cause a crash.
<* Source: Elena Stepanova
Peter (Stig) Edwards
Vasilis Lourdas
Link: http://secunia.com/advisories/57120/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MariaDB
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://mariadb.org/
Https://mariadb.com/kb/en/mariadb-5536-release-notes/
Https://mariadb.com/kb/en/mariadb-5536-changelog/
Https://mariadb.atlassian.net/browse/MDEV-5581
Https://mariadb.atlassian.net/browse/MDEV-714
Https://mariadb.atlassian.net/browse/MDEV-5655
Https://mariadb.atlassian.net/browse/MDEV-5505
Https://mariadb.atlassian.net/browse/MDEV-5617
Https://mariadb.atlassian.net/browse/MDEV-5629
MariaDB details: click here
MariaDB's: click here
Recommended reading:
Install LAMP (Apache with MariaDB and PHP) in CentOS/RHEL/Scientific Linux 6)