MySQL 5.5 < 5.5.33 Multiple Vulnerabilities

Medium Nessus Plugin ID 70462

Synopsis

The remote database server may be affected by multiple vulnerabilities.

Description

The version of MySQL 5.5 installed on the remote host is a version prior to 5.5.33. It is, therefore, potentially affected by vulnerabilities in the following components :

- Server Optimizer
- Server Replication

Solution

Upgrade to MySQL version 5.5.33 or later.

See Also

http://www.nessus.org/u?f2d5fae1

http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-33.html

Plugin Details

Severity: Medium

ID: 70462

File Name: mysql_5_5_33.nasl

Version: 1.6

Type: remote

Family: Databases

Published: 2013/10/16

Updated: 2018/11/15

Dependencies: 91823, 10719

Configuration: Enable paranoid mode

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:N

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:mysql

Required KB Items: Settings/ParanoidReport

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2013/07/31

Vulnerability Publication Date: 2013/10/15

Reference Information

CVE: CVE-2013-3839, CVE-2013-5807

BID: 63105, 63109