MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table crash.
History

Mon, 10 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Title mariadb: Crash in MariaDB Due to Improper Handling of Derived Tables
References
Metrics threat_severity

None

threat_severity

Moderate


Sat, 08 Mar 2025 23:00:00 +0000

Type Values Removed Values Added
Description MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table crash.
Weaknesses CWE-696
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-10T15:59:46.152Z

Reserved: 2025-03-08T00:00:00.000Z

Link: CVE-2023-52968

cve-icon Vulnrichment

Updated: 2025-03-10T15:59:43.194Z

cve-icon NVD

Status : Received

Published: 2025-03-08T23:15:13.173

Modified: 2025-03-08T23:15:13.173

Link: CVE-2023-52968

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-08T00:00:00Z

Links: CVE-2023-52968 - Bugzilla