CVE-2020-13249: Fedoraproject Fedora
High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.
libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.
Affected products
- Fedoraproject Fedora: version 31 only; version 32 only
- MariaDB Connector/c: before 3.1.8 (fixed in 3.1.8)
- Opensuse Leap: version 15.1 only
Published 2020-05-20. Last modified 2026-06-17.