Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handling). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.4 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H).
http://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
http://www.securityfocus.com/bid/106626
https://access.redhat.com/errata/RHSA-2019:1258
https://access.redhat.com/errata/RHSA-2019:2327
https://access.redhat.com/errata/RHSA-2019:2484
https://access.redhat.com/errata/RHSA-2019:2511
Source: MITRE
Published: 2019-01-16
Updated: 2020-08-24
Type: NVD-CWE-noinfo
Base Score: 3.8
Vector: AV:A/AC:M/Au:S/C:P/I:N/A:P
Impact Score: 4.9
Exploitability Score: 4.4
Severity: LOW
Base Score: 6.4
Vector: CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
Impact Score: 5.2
Exploitability Score: 1.2
Severity: MEDIUM
OR
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 5.6.0 to 5.6.42 (inclusive)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 5.7.0 to 5.7.24 (inclusive)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 8.0.0 to 8.0.13 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
145612 | CentOS 8 : mysql:8.0 (CESA-2019:2511) | Nessus | CentOS Local Security Checks | medium |
132455 | NewStart CGSL CORE 5.05 / MAIN 5.05 : mariadb Multiple Vulnerabilities (NS-SA-2019-0243) | Nessus | NewStart CGSL Local Security Checks | medium |
131817 | EulerOS 2.0 SP5 : mariadb (EulerOS-SA-2019-2543) | Nessus | Huawei Local Security Checks | medium |
129910 | NewStart CGSL CORE 5.04 / MAIN 5.04 : mariadb Multiple Vulnerabilities (NS-SA-2019-0197) | Nessus | NewStart CGSL Local Security Checks | medium |
129071 | Amazon Linux 2 : mariadb (ALAS-2019-1292) | Nessus | Amazon Linux Local Security Checks | medium |
128390 | CentOS 7 : mariadb (CESA-2019:2327) | Nessus | CentOS Local Security Checks | medium |
128240 | Scientific Linux Security Update : mariadb on SL7.x x86_64 (20190806) | Nessus | Scientific Linux Local Security Checks | medium |
127991 | RHEL 8 : mysql:8.0 (RHSA-2019:2511) | Nessus | Red Hat Local Security Checks | medium |
127983 | Oracle Linux 8 : mysql:8.0 (ELSA-2019-2511) | Nessus | Oracle Linux Local Security Checks | medium |
127712 | RHEL 7 : mariadb (RHSA-2019:2327) | Nessus | Red Hat Local Security Checks | medium |
126216 | Photon OS 2.0: Mysql PHSA-2019-2.0-0152 | Nessus | PhotonOS Local Security Checks | high |
700631 | MySQL 8.0.x < 8.0.15 Multiple Vulnerabilities (Jan 2019 CPU) | Nessus Network Monitor | Database | high |
700630 | MySQL 8.0.x < 8.0.14 Multiple Vulnerabilities (Jan 2019 CPU) | Nessus Network Monitor | Database | high |
700628 | MySQL 5.7.x < 5.7.25 Multiple Vulnerabilities (Jan 2019 CPU) | Nessus Network Monitor | Database | high |
700623 | MySQL 5.6.x < 5.6.43 Multiple Vulnerabilities (Jan 2019 CPU) | Nessus Network Monitor | Database | high |
123089 | Amazon Linux AMI : mysql57 (ALAS-2019-1181) | Nessus | Amazon Linux Local Security Checks | medium |
123086 | Amazon Linux AMI : mysql56 (ALAS-2019-1178) | Nessus | Amazon Linux Local Security Checks | medium |
122557 | Fedora 28 : community-mysql (2019-21b76d179e) | Nessus | Fedora Local Security Checks | medium |
122258 | MariaDB 5.5.x < 5.5.62 Multiple Vulnerabilities | Nessus | Databases | high |
121608 | openSUSE Security Update : mysql-community-server (openSUSE-2019-138) | Nessus | SuSE Local Security Checks | medium |
121406 | FreeBSD : MySQL -- multiple vulnerabilities (d3d02d3a-2242-11e9-b95c-b499baebfeaf) | Nessus | FreeBSD Local Security Checks | medium |
121346 | Ubuntu 16.04 LTS / 18.04 LTS / 18.10 : MySQL vulnerabilities (USN-3867-1) | Nessus | Ubuntu Local Security Checks | medium |
121229 | MySQL 8.0.x < 8.0.14 Multiple Vulnerabilities (Jan 2019 CPU) | Nessus | Databases | medium |
121228 | MySQL 5.7.x < 5.7.25 Multiple Vulnerabilities (Jan 2019 CPU) | Nessus | Databases | medium |
121227 | MySQL 5.6.x < 5.6.43 Multiple Vulnerabilities (Jan 2019 CPU) | Nessus | Databases | medium |
700392 | Oracle MySQL 5.7.x < 5.7.24 Multiple Vulnerabilities | Nessus Network Monitor | Database | medium |
700391 | Oracle MySQL 5.6.x < 5.6.42 Multiple Vulnerabilities | Nessus Network Monitor | Database | medium |
700390 | Oracle MySQL 8.0.x < 8.0.13 Multiple Vulnerabilities | Nessus Network Monitor | Database | medium |