ALT-PU-2022-5774-1
Package mariadb updated to version 10.6.9-alt1 for branch sisyphus_mipsel.
Closed vulnerabilities
BDU:2022-01641
Уязвимость библиотеки zlib, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-04075
Уязвимость функции prepare_inplace_add_virtual системы управления базами данных MariaDB, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность, доступность защищаемой информации
BDU:2022-04078
Уязвимость компонента sub_select системы управления базами данных MariaDB, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность, доступность защищаемой информации
BDU:2022-04079
Уязвимость функции st_select_lex_unit::exclude_level системы управления базами данных MariaDB, позволяющая нарушителю оказать воздействие на доступность защищаемой информации
BDU:2022-04082
Уязвимость функции __interceptor_memset (/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc) системы управления базами данных MariaDB, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность, доступность защищаемой информации
BDU:2022-05553
Уязвимость компонента dict0dict.cc системы управления базами данных MariaDB, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-03-28
CVE-2018-25032
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
- 20220516 APPLE-SA-2022-05-16-4 Security Update 2022-004 Catalina
- 20220516 APPLE-SA-2022-05-16-4 Security Update 2022-004 Catalina
- 20220516 APPLE-SA-2022-05-16-3 macOS Big Sur 11.6.6
- 20220516 APPLE-SA-2022-05-16-3 macOS Big Sur 11.6.6
- 20220516 APPLE-SA-2022-05-16-2 macOS Monterey 12.4
- 20220516 APPLE-SA-2022-05-16-2 macOS Monterey 12.4
- [oss-security] 20220325 Re: zlib memory corruption on deflate (i.e. compress)
- [oss-security] 20220325 Re: zlib memory corruption on deflate (i.e. compress)
- [oss-security] 20220326 Re: zlib memory corruption on deflate (i.e. compress)
- [oss-security] 20220326 Re: zlib memory corruption on deflate (i.e. compress)
- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
- https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
- https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
- https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
- https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
- https://github.com/madler/zlib/issues/605
- https://github.com/madler/zlib/issues/605
- [debian-lts-announce] 20220402 [SECURITY] [DLA 2968-1] zlib security update
- [debian-lts-announce] 20220402 [SECURITY] [DLA 2968-1] zlib security update
- [debian-lts-announce] 20220507 [SECURITY] [DLA 2993-1] libz-mingw-w64 security update
- [debian-lts-announce] 20220507 [SECURITY] [DLA 2993-1] libz-mingw-w64 security update
- [debian-lts-announce] 20220916 [SECURITY] [DLA 3114-1] mariadb-10.3 security update
- [debian-lts-announce] 20220916 [SECURITY] [DLA 3114-1] mariadb-10.3 security update
- FEDORA-2022-b58a85e167
- FEDORA-2022-b58a85e167
- FEDORA-2022-61cf1c64f6
- FEDORA-2022-61cf1c64f6
- FEDORA-2022-3a92250fd5
- FEDORA-2022-3a92250fd5
- FEDORA-2022-413a80a102
- FEDORA-2022-413a80a102
- FEDORA-2022-12b89e2aad
- FEDORA-2022-12b89e2aad
- FEDORA-2022-dbd2935e44
- FEDORA-2022-dbd2935e44
- GLSA-202210-42
- GLSA-202210-42
- https://security.netapp.com/advisory/ntap-20220526-0009/
- https://security.netapp.com/advisory/ntap-20220526-0009/
- https://security.netapp.com/advisory/ntap-20220729-0004/
- https://security.netapp.com/advisory/ntap-20220729-0004/
- https://support.apple.com/kb/HT213255
- https://support.apple.com/kb/HT213255
- https://support.apple.com/kb/HT213256
- https://support.apple.com/kb/HT213256
- https://support.apple.com/kb/HT213257
- https://support.apple.com/kb/HT213257
- DSA-5111
- DSA-5111
- https://www.openwall.com/lists/oss-security/2022/03/24/1
- https://www.openwall.com/lists/oss-security/2022/03/24/1
- https://www.openwall.com/lists/oss-security/2022/03/28/1
- https://www.openwall.com/lists/oss-security/2022/03/28/1
- https://www.openwall.com/lists/oss-security/2022/03/28/3
- https://www.openwall.com/lists/oss-security/2022/03/28/3
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Modified: 2024-11-21
CVE-2022-32081
MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.
- https://jira.mariadb.org/browse/MDEV-26420
- https://jira.mariadb.org/browse/MDEV-26420
- FEDORA-2022-e0e9a43546
- FEDORA-2022-e0e9a43546
- FEDORA-2022-333df1c4aa
- FEDORA-2022-333df1c4aa
- FEDORA-2022-cf88f807f9
- FEDORA-2022-cf88f807f9
- https://security.netapp.com/advisory/ntap-20220818-0005/
- https://security.netapp.com/advisory/ntap-20220818-0005/
Modified: 2024-11-21
CVE-2022-32082
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
- https://jira.mariadb.org/browse/MDEV-26433
- https://jira.mariadb.org/browse/MDEV-26433
- FEDORA-2022-e0e9a43546
- FEDORA-2022-e0e9a43546
- FEDORA-2022-333df1c4aa
- FEDORA-2022-333df1c4aa
- FEDORA-2022-cf88f807f9
- FEDORA-2022-cf88f807f9
- https://security.netapp.com/advisory/ntap-20220818-0005/
- https://security.netapp.com/advisory/ntap-20220818-0005/
Modified: 2024-11-21
CVE-2022-32084
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
- https://jira.mariadb.org/browse/MDEV-26427
- https://jira.mariadb.org/browse/MDEV-26427
- [debian-lts-announce] 20220916 [SECURITY] [DLA 3114-1] mariadb-10.3 security update
- [debian-lts-announce] 20220916 [SECURITY] [DLA 3114-1] mariadb-10.3 security update
- FEDORA-2022-e0e9a43546
- FEDORA-2022-e0e9a43546
- FEDORA-2022-333df1c4aa
- FEDORA-2022-333df1c4aa
- FEDORA-2022-cf88f807f9
- FEDORA-2022-cf88f807f9
- https://security.netapp.com/advisory/ntap-20220818-0005/
- https://security.netapp.com/advisory/ntap-20220818-0005/
Modified: 2024-11-21
CVE-2022-32089
MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.
- https://jira.mariadb.org/browse/MDEV-26410
- https://jira.mariadb.org/browse/MDEV-26410
- FEDORA-2022-e0e9a43546
- FEDORA-2022-e0e9a43546
- FEDORA-2022-333df1c4aa
- FEDORA-2022-333df1c4aa
- FEDORA-2022-cf88f807f9
- FEDORA-2022-cf88f807f9
- https://security.netapp.com/advisory/ntap-20220818-0005/
- https://security.netapp.com/advisory/ntap-20220818-0005/
Modified: 2024-11-21
CVE-2022-32091
MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.
- https://jira.mariadb.org/browse/MDEV-26431
- https://jira.mariadb.org/browse/MDEV-26431
- [debian-lts-announce] 20220916 [SECURITY] [DLA 3114-1] mariadb-10.3 security update
- [debian-lts-announce] 20220916 [SECURITY] [DLA 3114-1] mariadb-10.3 security update
- FEDORA-2022-e0e9a43546
- FEDORA-2022-e0e9a43546
- FEDORA-2022-333df1c4aa
- FEDORA-2022-333df1c4aa
- FEDORA-2022-cf88f807f9
- FEDORA-2022-cf88f807f9
- https://security.netapp.com/advisory/ntap-20220818-0005/
- https://security.netapp.com/advisory/ntap-20220818-0005/
Modified: 2024-11-21
CVE-2022-38791
In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.
- https://jira.mariadb.org/browse/MDEV-28719
- https://jira.mariadb.org/browse/MDEV-28719
- FEDORA-2022-e0e9a43546
- FEDORA-2022-e0e9a43546
- FEDORA-2022-333df1c4aa
- FEDORA-2022-333df1c4aa
- FEDORA-2022-cf88f807f9
- FEDORA-2022-cf88f807f9
- https://security.netapp.com/advisory/ntap-20221104-0008/
- https://security.netapp.com/advisory/ntap-20221104-0008/