CVE-2023-5157
published 2023-09-27CVE-2023-5157: A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.02%
78.8th percentile
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | galera-3 | < galera-4 26.4.13-1 (bookworm) | galera-4 26.4.13-1 (bookworm) |
| debian | galera-4 | < galera-4 26.4.13-1 (bookworm) | galera-4 26.4.13-1 (bookworm) |
| fedoraproject | fedora | — | — |
| mariadb | mariadb | < 10.3.36 | 10.3.36 |
| mariadb | mariadb | >= 10.4.0 < 10.4.26 | 10.4.26 |
| mariadb | mariadb | >= 10.5.0 < 10.5.17 | 10.5.17 |
| mariadb | mariadb | >= 10.6.0 < 10.6.9 | 10.6.9 |
| mariadb | mariadb | >= 10.7.0 < 10.7.5 | 10.7.5 |
| mariadb | mariadb | >= 10.8.0 < 10.8.4 | 10.8.4 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mariadb: node crashes with Transport endpoint is not connected mysqld got signal 6
vendor_redhat·2023-09-20·CVSS 7.5
CVE-2023-5157 [HIGH] CWE-400 mariadb: node crashes with Transport endpoint is not connected mysqld got signal 6
mariadb: node crashes with Transport endpoint is not connected mysqld got signal 6
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
Package: mariadb (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2023-5157: galera-3 - A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 456...
vendor_debian·2023·CVSS 7.5
CVE-2023-5157 [HIGH] CVE-2023-5157: galera-3 - A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 456...
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
Scope: local
bookworm: resolved
bullseye: resolved
GHSA
GHSA-6589-j38p-mm8c: A vulnerability was found in MariaDB
ghsa_unreviewed·2023-09-27
CVE-2023-5157 [HIGH] CWE-400 GHSA-6589-j38p-mm8c: A vulnerability was found in MariaDB
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
OSV
CVE-2023-5157: A vulnerability was found in MariaDB
osv·2023-09-27·CVSS 7.5
CVE-2023-5157 [HIGH] CVE-2023-5157: A vulnerability was found in MariaDB
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:5259https://access.redhat.com/errata/RHSA-2023:5683https://access.redhat.com/errata/RHSA-2023:5684https://access.redhat.com/errata/RHSA-2023:6821https://access.redhat.com/errata/RHSA-2023:6822https://access.redhat.com/errata/RHSA-2023:6883https://access.redhat.com/errata/RHSA-2023:7633https://access.redhat.com/security/cve/CVE-2023-5157https://bugzilla.redhat.com/show_bug.cgi?id=2240246https://access.redhat.com/errata/RHSA-2023:5683https://access.redhat.com/errata/RHSA-2023:5684https://access.redhat.com/errata/RHSA-2023:6821https://access.redhat.com/errata/RHSA-2023:6822https://access.redhat.com/errata/RHSA-2023:6883https://access.redhat.com/errata/RHSA-2023:7633https://access.redhat.com/security/cve/CVE-2023-5157https://bugzilla.redhat.com/show_bug.cgi?id=2240246
2023-09-27
Published