Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.securityfocus.com/bid/104766
http://www.securitytracker.com/id/1041294
https://access.redhat.com/errata/RHSA-2018:3655
https://lists.debian.org/debian-lts-announce/2018/11/msg00004.html
https://security.netapp.com/advisory/ntap-20180726-0002/
Source: MITRE
Published: 2018-07-18
Updated: 2019-10-03
Type: NVD-CWE-noinfo
Base Score: 4
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8
Severity: MEDIUM
Base Score: 6.5
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 2.8
Severity: MEDIUM
OR
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 5.5.0 to 5.5.60 (inclusive)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 5.6.0 to 5.6.40 (inclusive)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 5.7.0 to 5.7.22 (inclusive)
OR
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
OR
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
700627 | MySQL 5.7.x < 5.7.23 Multiple Vulnerabilities (July 2018 CPU) | Nessus Network Monitor | Database | high |
700616 | MySQL 5.5.x < 5.5.61 Multiple Vulnerabilities (July 2018 CPU) | Nessus Network Monitor | Database | high |
121976 | Photon OS 2.0: Mysql PHSA-2018-2.0-0079 | Nessus | PhotonOS Local Security Checks | medium |
121869 | Photon OS 1.0: Mysql PHSA-2018-1.0-0170 | Nessus | PhotonOS Local Security Checks | medium |
120915 | Fedora 28 : community-mysql (2018-f67fda3db6) | Nessus | Fedora Local Security Checks | medium |
118734 | Debian DLA-1566-1 : mysql-5.5 security update | Nessus | Debian Local Security Checks | medium |
117438 | Fedora 27 : community-mysql (2018-3a3c660bfa) | Nessus | Fedora Local Security Checks | medium |
112097 | Amazon Linux AMI : mysql57 (ALAS-2018-1070) | Nessus | Amazon Linux Local Security Checks | medium |
112096 | Amazon Linux AMI : mysql56 (ALAS-2018-1069) | Nessus | Amazon Linux Local Security Checks | medium |
112095 | Amazon Linux AMI : mysql55 (ALAS-2018-1068) | Nessus | Amazon Linux Local Security Checks | medium |
112014 | SUSE SLES11 Security Update : mysql (SUSE-SU-2018:2411-1) | Nessus | SuSE Local Security Checks | medium |
111963 | Photon OS 2.0: Mysql PHSA-2018-2.0-0079 (deprecated) | Nessus | PhotonOS Local Security Checks | medium |
111948 | Photon OS 1.0: Mysql PHSA-2018-1.0-0170 (deprecated) | Nessus | PhotonOS Local Security Checks | medium |
111625 | openSUSE Security Update : mysql-community-server (openSUSE-2018-844) | Nessus | SuSE Local Security Checks | medium |
111596 | FreeBSD : MySQL -- multiple vulnerabilities (909be51b-9b3b-11e8-add2-b499baebfeaf) | Nessus | FreeBSD Local Security Checks | medium |
111510 | Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS : MySQL vulnerabilities (USN-3725-1) | Nessus | Ubuntu Local Security Checks | medium |
111158 | MySQL 5.7.x < 5.7.23 Multiple Vulnerabilities (RPM Check) (July 2018 CPU) | Nessus | Databases | medium |
111157 | MySQL 5.7.x < 5.7.23 Multiple Vulnerabilities (July 2018 CPU) | Nessus | Databases | medium |
111156 | MySQL 5.6.x < 5.6.41 Multiple Vulnerabilities (RPM Check) (April 2018 CPU) | Nessus | Databases | medium |
111154 | MySQL 5.5.x < 5.5.61 Multiple Vulnerabilities (RPM Check) (July 2018 CPU) | Nessus | Databases | medium |
111153 | MySQL 5.5.x < 5.5.61 Multiple Vulnerabilities (July 2018 CPU) | Nessus | Databases | medium |