{"id":56732,"date":"2024-05-09T21:31:02","date_gmt":"2024-05-09T17:31:02","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/178508\/glsa-202405-25.txt"},"modified":"2024-05-09T21:31:02","modified_gmt":"2024-05-09T17:31:02","slug":"gentoo-linux-security-advisory-202405-25","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/gentoo-linux-security-advisory-202405-25\/","title":{"rendered":"Gentoo Linux Security Advisory 202405-25"},"content":{"rendered":"<p>&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211;<br \/>Gentoo Linux Security Advisory GLSA 202405-25<br \/>&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211;<br \/>https:\/\/security.gentoo.org\/<br \/>&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211;<\/p>\n<p>Severity: Normal<br \/>Title: MariaDB: Multiple Vulnerabilities<br \/>Date: May 08, 2024<br \/>Bugs: #699874, #822759, #832490, #838244, #847526, #856484, #891781<br \/>ID: 202405-25<\/p>\n<p>&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211;<\/p>\n<p>Synopsis<br \/>=======<br \/>Multiple vulnerabilities have been discovered in MariaDB, the worst fo<br \/>which can lead to arbitrary execution of code.<\/p>\n<p>Background<br \/>=========<br \/>MariaDB is an enhanced, drop-in replacement for MySQL.<\/p>\n<p>Affected packages<br \/>================<br \/>Package Vulnerable Unaffected<br \/>&#8212;&#8212;&#8212;&#8212;&#8211; &#8212;&#8212;&#8212;&#8212;&#8212; &#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>dev-db\/mariadb &lt; 10.11.3:10.11 &gt;= 10.11.3:10.11<br \/>&lt; 10.11.3:10.6 &gt;= 10.6.13:10.6<br \/>&lt; 10.11.3 &gt;= 10.6.13<\/p>\n<p>Description<br \/>==========<br \/>Multiple vulnerabilities have been discovered in MariaDB. Please review<br \/>the CVE identifiers referenced below for details.<\/p>\n<p>Impact<br \/>=====<br \/>Please review the referenced CVE identifiers for details.<\/p>\n<p>Workaround<br \/>=========<br \/>There is no known workaround at this time.<\/p>\n<p>Resolution<br \/>=========<br \/>All MariaDB 10.6 users should upgrade to the latest version:<\/p>\n<p># emerge &#8211;sync<br \/># emerge &#8211;ask &#8211;oneshot &#8211;verbose &#8220;&gt;\u00dev-db\/mariadb-10.11.3:10.6&#8221;<\/p>\n<p>All MariaDB 10.11 users should upgrade to the latest version:<\/p>\n<p># emerge &#8211;sync<br \/># emerge &#8211;ask &#8211;oneshot &#8211;verbose &#8220;&gt;\u00dev-db\/mariadb-10.11.3:10.11&#8221;<\/p>\n<p>References<br \/>=========<br \/>[ 1 ] CVE-2019-2938<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-2938<br \/>[ 2 ] CVE-2019-2974<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-2974<br \/>[ 3 ] CVE-2021-46661<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-46661<br \/>[ 4 ] CVE-2021-46662<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-46662<br \/>[ 5 ] CVE-2021-46663<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-46663<br \/>[ 6 ] CVE-2021-46664<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-46664<br \/>[ 7 ] CVE-2021-46665<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-46665<br \/>[ 8 ] CVE-2021-46666<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-46666<br \/>[ 9 ] CVE-2021-46667<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-46667<br \/>[ 10 ] CVE-2021-46668<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-46668<br \/>[ 11 ] CVE-2021-46669<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-46669<br \/>[ 12 ] CVE-2022-24048<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-24048<br \/>[ 13 ] CVE-2022-24050<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-24050<br \/>[ 14 ] CVE-2022-24051<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-24051<br \/>[ 15 ] CVE-2022-24052<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-24052<br \/>[ 16 ] CVE-2022-27376<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27376<br \/>[ 17 ] CVE-2022-27377<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27377<br \/>[ 18 ] CVE-2022-27378<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27378<br \/>[ 19 ] CVE-2022-27379<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27379<br \/>[ 20 ] CVE-2022-27380<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27380<br \/>[ 21 ] CVE-2022-27381<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27381<br \/>[ 22 ] CVE-2022-27382<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27382<br \/>[ 23 ] CVE-2022-27383<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27383<br \/>[ 24 ] CVE-2022-27384<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27384<br \/>[ 25 ] CVE-2022-27385<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27385<br \/>[ 26 ] CVE-2022-27386<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27386<br \/>[ 27 ] CVE-2022-27444<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27444<br \/>[ 28 ] CVE-2022-27445<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27445<br \/>[ 29 ] CVE-2022-27446<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27446<br \/>[ 30 ] CVE-2022-27447<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27447<br \/>[ 31 ] CVE-2022-27448<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27448<br \/>[ 32 ] CVE-2022-27449<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27449<br \/>[ 33 ] CVE-2022-27451<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27451<br \/>[ 34 ] CVE-2022-27452<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27452<br \/>[ 35 ] CVE-2022-27455<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27455<br \/>[ 36 ] CVE-2022-27456<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27456<br \/>[ 37 ] CVE-2022-27457<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27457<br \/>[ 38 ] CVE-2022-27458<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27458<br \/>[ 39 ] CVE-2022-31621<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-31621<br \/>[ 40 ] CVE-2022-31622<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-31622<br \/>[ 41 ] CVE-2022-31623<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-31623<br \/>[ 42 ] CVE-2022-31624<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-31624<br \/>[ 43 ] CVE-2022-32081<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-32081<br \/>[ 44 ] CVE-2022-32082<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-32082<br \/>[ 45 ] CVE-2022-32083<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-32083<br \/>[ 46 ] CVE-2022-32084<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-32084<br \/>[ 47 ] CVE-2022-32085<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-32085<br \/>[ 48 ] CVE-2022-32086<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-32086<br \/>[ 49 ] CVE-2022-32088<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-32088<br \/>[ 50 ] CVE-2022-32089<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-32089<br \/>[ 51 ] CVE-2022-32091<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-32091<br \/>[ 52 ] CVE-2022-38791<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-38791<br \/>[ 53 ] CVE-2022-47015<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-47015<br \/>[ 54 ] CVE-2023-5157<br \/>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-5157<\/p>\n<p>Availability<br \/>===========<br \/>This GLSA and any updates to it are available for viewing at<br \/>the Gentoo Security Website:<\/p>\n<p>https:\/\/security.gentoo.org\/glsa\/202405-25<\/p>\n<p>Concerns?<br \/>========<br \/>Security is a primary focus of Gentoo Linux and ensuring the<br \/>confidentiality and security of our users&#8217; machines is of utmost<br \/>importance to us. Any security concerns should be addressed to<br \/>security@gentoo.org or alternatively, you may file a bug at<br \/>https:\/\/bugs.gentoo.org.<\/p>\n<p>License<br \/>======<br \/>Copyright 2024 Gentoo Foundation, Inc; referenced text<br \/>belongs to its owner(s).<\/p>\n<p>The contents of this document are licensed under the<br \/>Creative Commons &#8211; Attribution \/ Share Alike license.<\/p>\n<p>https:\/\/creativecommons.org\/licenses\/by-sa\/2.5<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211;Gentoo Linux Security Advisory GLSA 202405-25&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-56732","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=56732"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56732\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=56732"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=56732"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=56732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}