Multiple Remote Denial of Service Vulnerabilities in MariaDB versions earlier than 5.5.35

Source: Internet
Author: User

Release date:
Updated on:

Affected Systems:
MariaDB <5.5.36
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65757

MariaDB is a MySQL branch version that uses the Maria storage engine.

MariaDB versions earlier than 5.5.36 have multiple implementation vulnerabilities, which can cause DoS attacks to malicious users.

1. An indirect NULL pointer reference error may occur when you process the prepared SELECT statement for some queries, which may cause a crash. To use this vulnerability successfully, you need to enable the "materialization" and "semijoin" optimizer.
2. An error occurred while processing kill query statements with some concurrent SQL queries, which may cause a crash;
3. An error occurred while parsing the NAME_CONST expression containing the AND/OR expression, which may cause a crash;
4. An error occurs when preparing a SELECT statement with an invalid group by value. An asserted error can be triggered;
5. If an error occurs when processing some SELECT statements with JOIN resolution, a crash may occur. To use this vulnerability successfully, you must set "SQL _mode" to "ONLY_FULL_GROUP_BY ".
6. An error occurs when processing some concurrent UPDATE statements, which can cause a crash.

<* Source: Elena Stepanova
Peter (Stig) Edwards
Vasilis Lourdas

Link: http://secunia.com/advisories/57120/
*>

Suggestion:
--------------------------------------------------------------------------------
Vendor patch:

MariaDB
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:

Http://mariadb.org/

Https://mariadb.com/kb/en/mariadb-5536-release-notes/
Https://mariadb.com/kb/en/mariadb-5536-changelog/
Https://mariadb.atlassian.net/browse/MDEV-5581
Https://mariadb.atlassian.net/browse/MDEV-714
Https://mariadb.atlassian.net/browse/MDEV-5655
Https://mariadb.atlassian.net/browse/MDEV-5505
Https://mariadb.atlassian.net/browse/MDEV-5617
Https://mariadb.atlassian.net/browse/MDEV-5629

MariaDB details: click here
MariaDB's: click here

Recommended reading:

Install LAMP (Apache with MariaDB and PHP) in CentOS/RHEL/Scientific Linux 6)

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.