CVE-2017-3313

LOW

Description

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS v3.0 Base Score 4.7 (Confidentiality impacts).

References

http://www.debian.org/security/2017/dsa-3767

http://www.debian.org/security/2017/dsa-3809

http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html

http://www.securityfocus.com/bid/95527

http://www.securitytracker.com/id/1037640

https://access.redhat.com/errata/RHSA-2017:2192

https://access.redhat.com/errata/RHSA-2017:2787

https://access.redhat.com/errata/RHSA-2017:2886

https://access.redhat.com/errata/RHSA-2018:0279

https://access.redhat.com/errata/RHSA-2018:0574

https://security.gentoo.org/glsa/201702-17

Details

Source: MITRE

Published: 2017-01-27

Updated: 2019-05-22

Type: CWE-200

Risk Information

CVSS v2.0

Base Score: 1.5

Vector: AV:L/AC:M/Au:S/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 2.7

Severity: LOW

CVSS v3.0

Base Score: 4.7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 5.5.0 to 5.5.53 (inclusive)

cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 5.6.0 to 5.6.34 (inclusive)

cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 5.7.0 to 5.7.16 (inclusive)

Configuration 2

OR

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Tenable Plugins

View all (34 total)

IDNameProductFamilySeverity
105077MariaDB 10.2.x < 10.2.10 Multiple VulnerabilitiesNessusDatabases
medium
103008EulerOS 2.0 SP2 : mariadb (EulerOS-SA-2017-1170)NessusHuawei Local Security Checks
medium
103007EulerOS 2.0 SP1 : mariadb (EulerOS-SA-2017-1169)NessusHuawei Local Security Checks
medium
102755CentOS 7 : mariadb (CESA-2017:2192)NessusCentOS Local Security Checks
medium
102648Scientific Linux Security Update : mariadb on SL7.x x86_64 (20170801)NessusScientific Linux Local Security Checks
medium
102299Oracle Linux 7 : mariadb (ELSA-2017-2192)NessusOracle Linux Local Security Checks
medium
102152RHEL 7 : mariadb (RHSA-2017:2192)NessusRed Hat Local Security Checks
medium
101568Fedora 26 : 3:mariadb (2017-09dd8907da)NessusFedora Local Security Checks
medium
100972Fedora 24 : 3:mariadb (2017-8425f676f2)NessusFedora Local Security Checks
medium
100857Fedora 25 : 3:mariadb (2017-2c0609b92a)NessusFedora Local Security Checks
medium
100611openSUSE Security Update : mariadb (openSUSE-2017-644)NessusSuSE Local Security Checks
medium
100245SUSE SLED12 / SLES12 Security Update : mariadb (SUSE-SU-2017:1315-1)NessusSuSE Local Security Checks
medium
100242SUSE SLES12 Security Update : mariadb (SUSE-SU-2017:1311-1)NessusSuSE Local Security Checks
medium
99670MariaDB 5.5.x < 5.5.55 / 10.0.x < 10.0.30 / 10.1.x < 10.1.22 / 10.2.x < 10.2.5 Multiple VulnerabilitiesNessusDatabases
medium
99034Slackware 14.2 / current : mariadb (SSA:2017-087-01)NessusSlackware Local Security Checks
medium
97757Debian DSA-3809-1 : mariadb-10.0 - security updateNessusDebian Local Security Checks
medium
97569openSUSE Security Update : mysql-community-server (openSUSE-2017-315)NessusSuSE Local Security Checks
medium
97278openSUSE Security Update : mysql-community-server (openSUSE-2017-258)NessusSuSE Local Security Checks
medium
97260GLSA-201702-17 : MySQL: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
97046SUSE SLES11 Security Update : mysql (SUSE-SU-2017:0408-1)NessusSuSE Local Security Checks
medium
96808Amazon Linux AMI : mysql56 (ALAS-2017-790)NessusAmazon Linux Local Security Checks
medium
96807Amazon Linux AMI : mysql55 (ALAS-2017-789)NessusAmazon Linux Local Security Checks
medium
96732Debian DLA-797-1 : mysql-5.5 security updateNessusDebian Local Security Checks
medium
96656Ubuntu 12.04 LTS / 14.04 LTS / 16.04 LTS / 16.10 : mysql-5.5, mysql-5.7 vulnerabilities (USN-3174-1)NessusUbuntu Local Security Checks
medium
96638Debian DSA-3767-1 : mysql-5.5 - security updateNessusDebian Local Security Checks
medium
96618FreeBSD : mysql -- multiple vulnerabilities (4d2f9d09-ddb7-11e6-a9a5-b499baebfeaf)NessusFreeBSD Local Security Checks
medium
9845Oracle MySQL 5.6.x < 5.6.35 Multiple VulnerabilitiesNessus Network MonitorDatabase
high
9844Oracle MySQL 5.5.x < 5.5.54 Multiple VulnerabilitiesNessus Network MonitorDatabase
high
95881MySQL 5.7.x < 5.7.17 Multiple Vulnerabilities (January 2017 CPU) (July 2017 CPU)NessusDatabases
medium
95880MySQL 5.7.x < 5.7.17 Multiple Vulnerabilities (January 2017 CPU) (July 2017 CPU)NessusDatabases
medium
95879MySQL 5.6.x < 5.6.35 Multiple Vulnerabilities (January 2017 CPU)NessusDatabases
medium
95878MySQL 5.6.x < 5.6.35 Multiple Vulnerabilities (January 2017 CPU)NessusDatabases
medium
95877MySQL 5.5.x < 5.5.54 Multiple Vulnerabilities (January 2017 CPU)NessusDatabases
medium
95876MySQL 5.5.x < 5.5.54 Multiple Vulnerabilities (January 2017 CPU)NessusDatabases
medium