========================================================================== Ubuntu Security Notice USN-4603-1 October 27, 2020 mariadb-10.1, mariadb-10.3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in MariaDB. Software Description: - mariadb-10.3: MariaDB database - mariadb-10.1: MariaDB database Details: It was discovered that MariaDB didn't properly validate the content of a packet received from a server. A remote attacker could use this vulnerability to sent a specialy crafted file to cause a denial of service. (CVE-2020-13249) It was discovered that MariaDB has other security issues. An attacker can cause a hang or frequently repeatable crash (denial of service). (CVE-2020-15180, CVE-2020-2752, CVE-2020-2760, CVE-2020-2812, CVE-2020-2814) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: mariadb-server 1:10.3.25-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: mariadb-server 1:10.1.47-0ubuntu0.18.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart MariaDB to make all the necessary changes. References: https://usn.ubuntu.com/4603-1 CVE-2020-13249, CVE-2020-15180, CVE-2020-2752, CVE-2020-2760, CVE-2020-2812, CVE-2020-2814 Package Information: https://launchpad.net/ubuntu/+source/mariadb-10.3/1:10.3.25-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/mariadb-10.1/1:10.1.47-0ubuntu0.18.04.1