MariaDB Server 10.x < 10.2 Multiple Vulnerabilities
medium Nessus Network Monitor Plugin ID 9754
Synopsis
The remote database server is affected by multiple attack vectors.
Description
The version of MariaDB installed on the remote host is 10.x prior to 10.2, and is affected by multiple vulnerabilities : - A flaw exists in the 'create_sort_index()' function in 'sql_select.cc' that is triggered during the handling of crafted 'SELECT' statements. This may allow an authenticated attacker to crash the database. - A flaw exists in the 'subselect_union_engine::no_rows()' function in 'item_subselect.cc' that is triggered during the handling of crafted 'SELECT' statements. This may allow an authenticated attacker to crash the database. - A flaw exists in log.cc that is triggered during the handling of specially crafted tabl_map events. This may allow an authenticated attacker to crash the database.