CVE-2019-2737
mariadbVulnerabilityCVSS 4.9Patched
No public exploitation has been reported so far. A fixed version is available (see the table below).
Recommended action: Update to the fixed version listed for your distribution using the native package manager.
Severity metrics
CVSS 3.1 : 4.9 MEDIUM · CVSS 2.0 : 4.0 MEDIUM
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredHigh
User interactionNone
ScopeUnchanged
Confidentiality impactNone
Integrity impactNone
Availability impactHigh
Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected & fixed versions by distribution
Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.
| Distribution | Package | Affected | Fixed version | Status |
|---|---|---|---|---|
| SUSE:HPE Helion OpenStack 8 | mariadb | - | 10.0.40.1-29.32.1 | fixed |
| SUSE:OpenStack Cloud 8 | mariadb | - | 10.0.40.1-29.32.1 | fixed |
| SUSE:OpenStack Cloud Crowbar 8 | mariadb | - | 10.0.40.1-29.32.1 | fixed |
| SUSE:Linux Enterprise Module for Server Applications 15 | mariadb | - | 10.2.29-3.23.1 | fixed |
| SUSE:Linux Enterprise Module for Server Applications 15 SP1 | mariadb | - | 10.2.29-3.23.1 | fixed |
| SUSE:OpenStack Cloud 9 | mariadb | - | 10.2.29-3.22.1 | fixed |
| SUSE:OpenStack Cloud Crowbar 9 | mariadb | - | 10.2.29-3.22.1 | fixed |
| SUSE:Linux Enterprise Desktop 12 SP4 | mariadb | - | 10.2.29-3.22.1 | fixed |
| SUSE:Linux Enterprise Server 12 SP4 | mariadb | - | 10.2.29-3.22.1 | fixed |
| SUSE:Linux Enterprise Server for SAP Applications 12 SP4 | mariadb | - | 10.2.29-3.22.1 | fixed |
| SUSE:Linux Enterprise Server 12 SP5 | mariadb | - | 10.2.29-3.22.1 | fixed |
| SUSE:Linux Enterprise Server for SAP Applications 12 SP5 | mariadb | - | 10.2.29-3.22.1 | fixed |
| SUSE:HPE Helion OpenStack 8 | mariadb | - | 10.2.31-4.17.3 | fixed |
| SUSE:OpenStack Cloud 8 | mariadb | - | 10.2.31-4.17.3 | fixed |
| SUSE:OpenStack Cloud Crowbar 8 | mariadb | - | 10.2.31-4.17.3 | fixed |
| SUSE:OpenStack Cloud 7 | mariadb | - | 10.2.31-16.1 | fixed |
| openSUSE:Leap 15.1 | mariadb | - | 10.2.29-lp151.2.9.1 | fixed |
| Red Hat:enterprise_linux:8::appstream | mariadb | - | 3:10.3.17-1.module+el8.1.0+3974+90eded84 | fixed |
| Red Hat:enterprise_linux:8::crb | mariadb | - | 3:10.3.17-1.module+el8.1.0+3974+90eded84 | fixed |
| Red Hat:enterprise_linux:7::client | mariadb | - | 1:5.5.65-1.el7 | fixed |
| Red Hat:enterprise_linux:7::computenode | mariadb | - | 1:5.5.65-1.el7 | fixed |
| Red Hat:enterprise_linux:7::server | mariadb | - | 1:5.5.65-1.el7 | fixed |
| Red Hat:enterprise_linux:7::workstation | mariadb | - | 1:5.5.65-1.el7 | fixed |
| Red Hat:rhel_e4s:8.0::appstream | mariadb | - | 3:10.3.27-3.module+el8.0.0+9160+9822c5c7 | fixed |
| Red Hat:enterprise_linux:8::appstream | mariadb-server | - | 3:10.3.17-1.module+el8.1.0+3974+90eded84 | fixed |
| Red Hat:enterprise_linux:8::crb | mariadb-server | - | 3:10.3.17-1.module+el8.1.0+3974+90eded84 | fixed |
| Red Hat:enterprise_linux:7::client | mariadb-server | - | 1:5.5.65-1.el7 | fixed |
| Red Hat:enterprise_linux:7::computenode | mariadb-server | - | 1:5.5.65-1.el7 | fixed |
| Red Hat:enterprise_linux:7::server | mariadb-server | - | 1:5.5.65-1.el7 | fixed |
| Red Hat:enterprise_linux:7::workstation | mariadb-server | - | 1:5.5.65-1.el7 | fixed |
| Red Hat:rhel_e4s:8.0::appstream | mariadb-server | - | 3:10.3.27-3.module+el8.0.0+9160+9822c5c7 | fixed |