Multiple vulnerabilities have been found in MariaDB, the worst of which could result in privilege escalation.
Package | dev-db/mariadb on all architectures |
---|---|
Affected versions | < 10.5.8 |
Unaffected versions | >= 10.2.36 >= 10.3.27 >= 10.4.17 >= 10.5.8 |
MariaDB is an enhanced, drop-in replacement for MySQL.
Multiple vulnerabilities have been discovered in MariaDB. Please review the CVE identifiers referenced below for details.
Please review the referenced CVE identifiers for details.
There is no known workaround at this time.
All MariaDB 10.2.x users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.2.36:10.2"
All MariaDB 10.3.x users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.3.27:10.3"
All MariaDB 10.4.x users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.4.17:10.4"
All MariaDB 10.5.x users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.5.8:10.5"
Release date
December 07, 2020
Latest revision
December 07, 2020: 1
Severity
normal
Exploitable
remote
Bugzilla entries