CVE-2024-27766
Description
An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
CWE
- CWE-94 — CWE-94 Improper Control of Generation of Code ('Code Injection')
Affected
- n/a / n/a — v=n/a [affected]
CVSS
- (none)
References
Source
cvelistV5-main/cves/2024/27xxx/CVE-2024-27766.json