U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-27458

Change History

CVE Modified by MITRE 5/01/2024 6:15:09 PM

Action Type Old Value New Value
Removed CPE Configuration
OR
     
          *cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* versions from (including) 10.3.0 from (excluding) 10.3.35
          *cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* versions from (including) 10.7.0 from (excluding) 10.7.4
          *cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* versions from (including) 10.4.0 from (excluding) 10.4.25
          *cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* versions from (including) 10.5.0 from (excluding) 10.5.16
          *cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* versions from (including) 10.6.0 from (excluding) 10.6.8

								
						
Removed CPE Configuration
OR
     
          *cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

								
						
Removed CVSS V2
NIST (AV:N/AC:L/Au:N/C:N/I:N/A:P)

								
						
Removed CVSS V3.1
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

								
						
Removed CWE
NIST CWE-416

								
						
Changed Description
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Binary_string::free_buffer() at /sql/sql_string.h.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-27447. Reason: This candidate is a reservation duplicate of CVE-2022-27447. Notes: All CVE users should reference CVE-2022-27447 instead of this candidate.
Removed Reference
MITRE https://jira.mariadb.org/browse/MDEV-28099

								
						
Removed Reference
MITRE https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html

								
						
Removed Reference
MITRE https://security.netapp.com/advisory/ntap-20220526-0007/

								
						

CVE Rejected by MITRE 5/01/2024 6:15:09 PM

Action Type Old Value New Value

CVE Translated by MITRE 5/01/2024 6:15:09 PM

Action Type Old Value New Value
Removed Translation
Title: el componente Binary_string::free_buffer() en /sql/sql_string.h en MariaDB Server
Description: Se ha detectado que MariaDB Server versiones v10.6.3 y anteriores, contienen un uso de memoria previamente liberada en el componente Binary_string::free_buffer() en /sql/sql_string.h