CVE-2022-47015

MEDIUM6.5EPSS 0.15%

mariadb-10.3 - security update

Published: 1/20/2023Modified: 4/28/2026
Also known as:ALPINE-CVE-2022-47015DEBIAN-CVE-2022-47015

Description

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

Affected packages (7)

  • Alpine/mariadbfrom 0, < 10.6.13-r0
  • Bitnami/mariadb>= 10.3.0, < 10.3.39, >= 10.4.0, < 10.4.29, >= 10.5.0, < 10.5.20, >= 10.6.0, < 10.6.13, >= 10.8.0, < 10.8.8, >= 10.9.0, < 10.9.6, >= 10.10.0, < 10.10.4, >= 10.11.0, < 10.11.3
  • Bitnami/mariadb-min>= 10.3.0, < 10.3.39, >= 10.4.0, < 10.4.29, >= 10.5.0, < 10.5.20, >= 10.6.0, < 10.6.13, >= 10.8.0, < 10.8.8, >= 10.9.0, < 10.9.6, >= 10.10.0, < 10.10.4, >= 10.11.0, < 10.11.3
  • Bitnami/mysql-client>= 10.3.0, < 10.3.39, >= 10.4.0, < 10.4.29, >= 10.5.0, < 10.5.20, >= 10.6.0, < 10.6.13, >= 10.8.0, < 10.8.8, >= 10.9.0, < 10.9.6, >= 10.10.0, < 10.10.4, >= 10.11.0, < 10.11.3
  • Debian/mariadbfrom 0, < 1:10.11.3-1
  • Debian/mariadb-10.3from 0, < 1:10.3.39-0+deb10u1
  • Debian/mariadb-10.5from 0, < 1:10.5.20-0+deb11u1

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References (8)