PT-2015-2567 · Oracle+4 · Mysql Server+3

Published

2015-10-20

·

Updated

2018-05-03

·

CVE-2015-4766

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle MySQL Server versions 5.6.25 and earlier
Description The issue is related to errors in the code of the Server: Security: Firewall subcomponent of the MySQL database management system. It allows an attacker, potentially with network access, to cause a denial of service (DOS) by exploiting the vulnerability, which can lead to a hang or frequently repeatable crash of the MySQL Server. The vulnerability is easily exploitable and can be compromised by a high-privileged attacker via multiple protocols.
Recommendations For Oracle MySQL Server versions 5.6.25 and earlier, update to a version that includes the fix for this issue to prevent potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1647
BDU:2015-11932
CVE-2015-4766
OPENSUSE-SU-2015_2243-1
RHSA-2015:1630
SUSE-SU-2015:2303-1
USN-2781-1

Affected Products

Alt Linux
Mysql Server
Suse
Ubuntu