PT-2016-7484 · Oracle+2 · Mysql Server+1

Publicado

2016-10-18

·

Atualizado

2018-05-03

·

CVE-2016-8289

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.7.13 and earlier
Description The issue allows local users to affect integrity and availability via vectors related to Server: InnoDB. It is an easily exploitable vulnerability that allows a high privileged attacker with network access via multiple protocols to compromise MySQL Server, resulting in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Server.
Recommendations For Oracle MySQL versions 5.7.13 and earlier, update to a version later than 5.7.13 to resolve the issue. As a temporary workaround, consider restricting network access to the MySQL Server to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1647
CVE-2016-8289

Produtos afetados

Alt Linux
Mysql Server