CVE-2022-47015NULL Pointer Dereference in Mariadb

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 55.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateJan 25

Description

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDmariadb/mariadb10.3.010.3.39+7
Debianmariadb/mariadb< 1:10.11.3-1+2

Patches

🔴Vulnerability Details

4
OSV
mariadb, mariadb-10.3, mariadb-10.6 vulnerabilities2024-01-25
GHSA
GHSA-hc8h-974x-98hr: MariaDB Server before 102023-01-20
CVEList
CVE-2022-47015: MariaDB Server before 102023-01-20
OSV
CVE-2022-47015: MariaDB Server before 102023-01-20

📋Vendor Advisories

4
Ubuntu
MariaDB vulnerabilities2024-01-25
Microsoft
MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.2023-01-10
Red Hat
mariadb: NULL pointer dereference in spider_db_mbase::print_warnings()2022-09-27
Debian
CVE-2022-47015: mariadb - MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It...2022