Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to CVE-2020-13249 libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.
Remediation
Upgrade mariadb-connector-c
to version or higher.
References
CVSS Score
8.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-13249
- Snyk ID
- SNYK-ALPINE39-MARIADBCONNECTORC-1050737
- Disclosed
- 20 May, 2020
- Published
- 12 Dec, 2020