mariadb-connector-c: Improper validation of content in a OK packet received from server (CVE-2020-13249)
libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a client.
Fixed In Version:
mariadb-connector-c 3.1.8
References:
https://nvd.nist.gov/vuln/detail/CVE-2020-13249 https://github.com/mariadb-corporation/mariadb-connector-c/compare/v3.1.7...v3.1.8
Patch:
Affected branches:
-
master (5173f8ea) -
3.11-stable -
3.10-stable -
3.9-stable
Edited by Leo