PT-2016-6587 · Oracle+6 · Mysql Server+5

Published

2015-11-30

·

Updated

2022-07-20

·

CVE-2016-5612

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.5.50 and earlier Oracle MySQL versions 5.6.31 and earlier Oracle MySQL versions 5.7.13 and earlier
Description The issue allows remote authenticated users to affect availability via vectors related to DML, potentially resulting in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Server. This can be exploited by a high privileged attacker with network access via multiple protocols.
Recommendations For versions 5.5.50 and earlier, update to a version later than 5.5.50 to resolve the issue. For versions 5.6.31 and earlier, update to a version later than 5.6.31 to resolve the issue. For versions 5.7.13 and earlier, update to a version later than 5.7.13 to resolve the issue. As a temporary workaround, consider restricting access to DML operations to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2015-2037
ALT-PU-2016-2238
CESA-2016_2595
CVE-2016-5612
OPENSUSE-SU-2016_2746-1
OPENSUSE-SU-2016_2769-1
OPENSUSE-SU-2016_2788-1
OPENSUSE-SU-2024:10200-1
RHSA-2016:1601
RHSA-2016:2130
RHSA-2016:2131
RHSA-2016:2595
RHSA-2016:2927
RHSA-2016_2595

Affected Products

Alt Linux
Centos
Mariadb Server
Mysql Server
Red Hat
Suse