PT-2017-15777 · Oracle+3 · Mysql Server+2

Publicado

2017-01-17

·

Atualizado

2018-05-03

·

CVE-2017-3319

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.7.16 and earlier
Description The issue affects the MySQL Server component, specifically the Server: X Plugin subcomponent. It allows an attacker with network access via multiple protocols to compromise the MySQL Server. Successful attacks can result in unauthorized read access to a subset of MySQL Server accessible data or cause a hang or frequently repeatable crash of the MySQL Server.
Recommendations For versions 5.7.16 and earlier, update to a version later than 5.7.16 to resolve the issue. As a temporary workaround, consider restricting network access to the MySQL Server to minimize the risk of exploitation.

Correção

DoS

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1647
CVE-2017-3319
RHSA-2017:2886
USN-3174-1

Produtos afetados

Alt Linux
Mysql Server
Ubuntu