Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-8078

Memory disclosure/buffer overread on audit plugin

Details

    • 5.5.44

    Description

      after executing a query, a buffer overread is happening while writing the query on the audit file. this bug will happen with the current version (1.3.0)

      the query looks like: SET PASSWORD FOR `monitor`@`localhost` = password('test123');
      the output looks like: 20150429 11:54:31,hostname123,root,localhost,109,442,QUERY,,'SET PASSWORD FOR `monitor`@`localhost`=<secret>*****�)1P��)root)�-��XM.localhost

      Attachments

        Activity

          h0nIg Hans-Joachim Kliemeck created issue -
          h0nIg Hans-Joachim Kliemeck made changes -
          Field Original Value New Value
          Description after executing a query, a buffer overread is happening while writing the query on the audit file.

          the query looks like: SET PASSWORD FOR `monitor`@`localhost` = password('test123');
          the output looks like: 20150429 11:54:31,test-iason,root,localhost,109,442,QUERY,,'SET PASSWORD FOR `monitor`@`localhost`=<secret>*****�)1P��)root)�-��XM.localhost
          after executing a query, a buffer overread is happening while writing the query on the audit file. this bug will happen with the current version (1.3.0)

          the query looks like: SET PASSWORD FOR `monitor`@`localhost` = password('test123');
          the output looks like: 20150429 11:54:31,test-iason,root,localhost,109,442,QUERY,,'SET PASSWORD FOR `monitor`@`localhost`=<secret>*****�)1P��)root)�-��XM.localhost
          h0nIg Hans-Joachim Kliemeck made changes -
          Description after executing a query, a buffer overread is happening while writing the query on the audit file. this bug will happen with the current version (1.3.0)

          the query looks like: SET PASSWORD FOR `monitor`@`localhost` = password('test123');
          the output looks like: 20150429 11:54:31,test-iason,root,localhost,109,442,QUERY,,'SET PASSWORD FOR `monitor`@`localhost`=<secret>*****�)1P��)root)�-��XM.localhost
          after executing a query, a buffer overread is happening while writing the query on the audit file. this bug will happen with the current version (1.3.0)

          the query looks like: SET PASSWORD FOR `monitor`@`localhost` = password('test123');
          the output looks like: 20150429 11:54:31,hostname123,root,localhost,109,442,QUERY,,'SET PASSWORD FOR `monitor`@`localhost`=<secret>*****�)1P��)root)�-��XM.localhost
          elenst Elena Stepanova made changes -
          Labels audit server_audit audit need_feedback server_audit
          elenst Elena Stepanova made changes -
          Fix Version/s 10.1 [ 16100 ]
          Fix Version/s 10.0 [ 16000 ]
          Fix Version/s 5.5 [ 15800 ]
          Affects Version/s N/A [ 14700 ]
          Affects Version/s 5.5.43 [ 18601 ]
          Assignee Alexey Botchkov [ holyfoot ]
          Labels audit need_feedback server_audit audit server_audit verified
          ratzpo Rasmus Johansson (Inactive) made changes -
          Workflow MariaDB v2 [ 60725 ] MariaDB v3 [ 66792 ]
          serg Sergei Golubchik made changes -
          Sprint Sprint 1 [ 4 ]
          holyfoot Alexey Botchkov made changes -
          Status Open [ 1 ] In Progress [ 3 ]
          holyfoot Alexey Botchkov made changes -
          Fix Version/s 5.5.44 [ 19100 ]
          Fix Version/s 5.5 [ 15800 ]
          Fix Version/s 10.0 [ 16000 ]
          Fix Version/s 10.1 [ 16100 ]
          Resolution Fixed [ 1 ]
          Status In Progress [ 3 ] Closed [ 6 ]
          serg Sergei Golubchik made changes -
          Workflow MariaDB v3 [ 66792 ] MariaDB v4 [ 149111 ]

          People

            holyfoot Alexey Botchkov
            h0nIg Hans-Joachim Kliemeck
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.