Bug 26167 - mariadb possible new issue CVE-2020-7221
Summary: mariadb possible new issue CVE-2020-7221
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Marc Krämer
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-02-04 15:57 CET by David Walser
Modified: 2020-02-04 17:06 CET (History)
0 users

See Also:
Source RPM: mariadb-10.4.12-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-02-04 15:57:55 CET
An issue in MariaDB has been announced today (February 4):
https://www.openwall.com/lists/oss-security/2020/02/04/1

The announcement says that upstream attempted to fix it in 10.4.12, but also suggested that some packaging changes may be needed to fully address the issue.

I don't know if the version in Mageia 7 also contains the affected auth_pam_tool.
Comment 1 Marc Krämer 2020-02-04 17:06:35 CET
as far as I can tell mga7 is not affected. the script mysql_install_db does not contain the named dir/executeables.
in cauldron we have a separated package for the pam plugin, which is not installed by default.
Adressed issue in cauldron.

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.