Details
-
Bug
-
Status: Closed (View Workflow)
-
Blocker
-
Resolution: Fixed
-
3.3.19, 3.4.9
-
None
Description
unpack_fields() in libmariadb/mariadb_lib.c parses 12 bytes of fixed-header metadata (charsetnr, length, type, flags, decimals) from each column descriptor without validating that the row data contains at least 12 bytes. A malicious or rogue server can send a truncated field descriptor payload ($0\text{--}11$ bytes) and trigger out-of-bounds reads on the client process.Originally reported by: Aisle Research
Originally reported by Aisle Research
Attachments
Issue Links
- links to