Skip to content

When updates are applied to the MariaDB software, any software components that have been replaced or made unnecessary must be removed.

An XCCDF Rule

Description

<VulnDiscussion>Previous versions of MariaDB components that are not removed from the information system after updates have been installed may be exploited by adversaries. MariaDB may remove older versions of software automatically from the information system. In other cases, manual review and removal will be required. In planning installations and upgrades, organizations must include steps (automated, manual, or both) to identify and remove the outdated modules. A transition period may be necessary when both the old and the new software are required. This should be taken into account in the planning.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-253744r961677_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

If after the upgrade outdated packages remain, update them if needed or remove. Example: 

$ sudo yum remove package_name