Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yiyuaner

#33691of 53,633
7.8Total CVSS
Vulnerabilities · 1
PT-2023-15909
7.8
2022-07-17
Oracle · Mysql Server · CVE-2022-4899
**Name of the Vulnerable Software and Affected Versions** zstd version 1.4.10 MySQL Server versions 8.0.33 and earlier **Description** A vulnerability was found where an attacker can supply an empty string as an argument to the command line tool to cause buffer overrun. This issue can be exploited by a high-privileged attacker with network access via multiple protocols to compromise MySQL Server, potentially resulting in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Server. **Recommendations** For zstd version 1.4.10, consider disabling the command line tool until a patch is available. For MySQL Server versions 8.0.33 and earlier, update to a version later than 8.0.33 to resolve the issue. As a temporary workaround, restrict access to the command line tool to minimize the risk of exploitation.