mariadb@0.0.1-security

fast mariadb or mysql connector.

  • latest version

    3.5.4

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    1 months ago

  • Direct Vulnerabilities

    Known vulnerabilities in the mariadb package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Insufficiently Protected Credentials

    Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the SendPamAuthPacketFactory function. An attacker can intercept sensitive credentials by performing a man-in-the-middle attack or controlling a malicious server that issues an Authentication Switch Request for the dialog plugin over an insecure connection.

    Note: This is only exploitable if connections occur over plain TCP (`sslMode'='DISABLE') or a TLS mode that only verifies server identity via self-signed-certificate fingerprint validation, and the attacker can occupy an on-path position or control the server.

    How to fix Insufficiently Protected Credentials?

    Upgrade mariadb to version 3.5.3 or higher.

    <3.5.3
    • H
    Improper Encoding or Escaping of Output

    Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output in the client-side escaping of Buffer parameters under certain multi-byte client character sets, specifically big5, gbk, sjis, cp932, or gb18030. An attacker can gain unauthorized access to or modify data by supplying crafted input that manipulates the escaping process, causing the intended string literal to be terminated and arbitrary SQL to be executed.

    Note: This is only exploitable if the connection's client character set is set to one of the affected multi-byte charsets and untrusted data is bound as a Buffer parameter.

    How to fix Improper Encoding or Escaping of Output?

    Upgrade mariadb to version 3.5.3 or higher.

    <3.5.3
    • H
    Insufficiently Protected Credentials

    Affected versions of this package are vulnerable to Insufficiently Protected Credentials in the authentication. An attacker can intercept sensitive credentials by performing a man-in-the-middle attack during the initial handshake.

    Note: This is only exploitable if SSL/TLS is enabled without providing a CA or server certificate and the connection relies solely on fingerprint validation.

    How to fix Insufficiently Protected Credentials?

    Upgrade mariadb to version 3.5.3 or higher.

    <3.5.3
    • H
    Malicious Package

    mariadb is a one of 37 malicious packages that use typosquatting to bait unknowing users to install them. These packages, which carry similar names to an original package, offer all the functionality of their original, but also include a code snippet that sends all your environment variables to a remote server controlled by malicious operators when your code is running.

    This is especially dangerous in production runtime environments, where environment variables tend to consist of keys, passwords, tokens and other secrets.

    On August 1st, 2017 npm deprecated all malicious typosquatting libraries from this list.

    The full list of packages are:

    babelcli - v1.0.1 - Babel CLI for Nodejs
    crossenv - v6.1.1 - Run scripts that set and use environment variables across platforms
    cross-env.js - v5.0.1
    d3.js - v1.0.1 - d3.js for Nodejs
    fabric-js - v1.7.18 - Object model for HTML5 canvas, and SVG-to-canvas parser. Backed by jsdom and node-canvas.
    ffmepg - v0.0.1 - FFmpeg for Nodejs
    gruntcli - v1.0.1 - Grunt CLI for Nodejs
    http-proxy.js - v0.11.3 - Node.js proxy tools
    jquery.js - v3.2.2-pre - jquery.js for Nodejs
    mariadb - v2.13.0 - A node.js driver for mysql. It is written in JavaScript, does not require compiling, and is 100% MIT licensed.
    mongose - v4.11.3 - Mongoose MongoDB ODM
    mssql.js - v4.0.5 - Microsoft SQL Server client for Node.js.
    mssql-node - v4.0.5 - Microsoft SQL Server client for Node.js.
    mysqljs - v2.13.0 - A node.js driver for mysql. It is written in JavaScript, does not require compiling, and is 100% MIT licensed.
    nodecaffe - v0.0.1 - caffe for Nodejs
    nodefabric - v1.7.18 - Object model for HTML5 canvas, and SVG-to-canvas parser. Backed by jsdom and node-canvas.
    node-fabric - v1.7.18 - Object model for HTML5 canvas, and SVG-to-canvas parser. Backed by jsdom and node-canvas.
    nodeffmpeg - v0.0.1 - FFmpeg for Nodejs
    nodemailer-js - v4.0.1 - Easy as cake e-mail sending from your Node.js applications
    nodemailer.js - v4.0.1 - Easy as cake e-mail sending from your Node.js applications
    nodemssql - v4.0.5 - Microsoft SQL Server client for Node.js.
    node-opencv - v1.0.1 - OpenCV for Nodejs
    node-opensl - v1.0.1 - OpenSSL for Nodejs
    node-openssl - v1.0.1 - OpenSSL for Nodejs
    noderequest - v2.81.0 - Simplified HTTP request client.
    nodesass - v4.5.3 - Wrapper around libsass
    nodesqlite - v2.8.1 - SQLite client for Node.js applications with SQL-based migrations API
    node-sqlite - v2.8.1 - SQLite client for Node.js applications with SQL-based migrations API
    node-tkinter - v1.0.1 - Tkinter for Nodejs
    opencv.js - v1.0.1 - OpenCV for Nodejs
    openssl.js - v1.0.1 - OpenSSL for Nodejs
    proxy.js - v0.11.3 - Node.js proxy tools
    shadowsock - v2.0.1 - A tunnel proxy that help you get through firewalls
    smb - v1.5.1 - A Pure JavaScript SMB Server Implementation
    sqlite.js - v2.8.1 - SQLite client for Node.js applications with SQL-based migrations API
    sqliter - v2.8.1 - SQLite client for Node.js applications with SQL-based migrations API
    sqlserver - v4.0.5 - Microsoft SQL Server client for Node.js.
    tkinter - v1.0.1 - Tkinter for Nodejs
    

    How to fix Malicious Package?

    Avoid usage of this package altogether.

    <0.7.0>=1.0.1 <2.0.0-alpha