CVE-2022-47015

Name
CVE-2022-47015
Description
MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/MariaDB/server/commit/be0a46b3d52b58956fd0d47d040b9f4514406954
CONFIRM https://security.netapp.com/advisory/ntap-20230309-0009/
MLIST https://lists.debian.org/debian-lts-announce/2023/06/msg00005.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O22PO3Q6TRSNJI2A2WTJH3VVCHEKBF6C/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SUQ33SPQCZQD63TWAM3XKFNVNFRGPFYU/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* mariadb >= 10.3.34 <= 10.9.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mariadb 3.14-main 10.5.19-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mariadb 3.15-main 10.6.14-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mariadb 3.17-main 10.6.16-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mariadb 3.16-main 10.6.16-r0 Natanael Copa <ncopa@alpinelinux.org> fixed