From 6abbf81ef2f298e3221ff5e67a1f3c5f23958212 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 14 Dec 2020 13:26:14 +0000 Subject: gentoo resync : 14.12.2020 --- metadata/glsa/glsa-202012-08.xml | 74 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) create mode 100644 metadata/glsa/glsa-202012-08.xml (limited to 'metadata/glsa/glsa-202012-08.xml') diff --git a/metadata/glsa/glsa-202012-08.xml b/metadata/glsa/glsa-202012-08.xml new file mode 100644 index 000000000000..468beb7d8a9a --- /dev/null +++ b/metadata/glsa/glsa-202012-08.xml @@ -0,0 +1,74 @@ + + + + MariaDB: Multiple vulnerabilities + Multiple vulnerabilities have been found in MariaDB, the worst of + which could result in privilege escalation. + + mariadb + 2020-12-07 + 2020-12-07 + 722782 + remote + + + 10.2.36 + 10.3.27 + 10.4.17 + 10.5.8 + 10.5.8 + + + +

MariaDB is an enhanced, drop-in replacement for MySQL.

+
+ +

Multiple vulnerabilities have been discovered in MariaDB. Please review + the CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All MariaDB 10.2.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.2.36:10.2" + + +

All MariaDB 10.3.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.3.27:10.3" + + +

All MariaDB 10.4.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.4.17:10.4" + + +

All MariaDB 10.5.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/mariadb-10.5.8:10.5" + + +
+ + CVE-2020-2752 + CVE-2020-2760 + CVE-2020-2812 + CVE-2020-2814 + + sam_c + whissi +
-- cgit v1.2.3