PT-2016-6602 · Oracle +6 · Mysql Server +5
Published
2016-09-13
·
Updated
2023-12-29
·
CVE-2016-5629
4.9
Medium
Base vector | Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Oracle MySQL versions 5.5.51 and earlier
Oracle MySQL versions 5.6.32 and earlier
Oracle MySQL versions 5.7.14 and earlier
Description:
The issue allows remote administrators to affect availability via vectors related to Server: Federated. It is an easily exploitable vulnerability that can be compromised by a high privileged attacker with network access via multiple protocols, resulting in the unauthorized ability to cause a hang or frequently repeatable crash of MySQL Server.
Recommendations:
For Oracle MySQL versions 5.5.51 and earlier, update to a version later than 5.5.51 to resolve the issue.
For Oracle MySQL versions 5.6.32 and earlier, update to a version later than 5.6.32 to resolve the issue.
For Oracle MySQL versions 5.7.14 and earlier, update to a version later than 5.7.14 to resolve the issue.
As a temporary workaround, consider restricting access to the Server: Federated component to minimize the risk of exploitation.
Exploit
Fix
Related Identifiers
Affected Products
References · 649
- 🔥 https://github.com/MAYASEVEN/CVE-2016-6662⭐ 27 🔗 11 · Exploit
- 🔥 https://github.com/firebroo/CVE-2016-6663⭐ 5 🔗 3 · Exploit
- 🔥 https://github.com/OsandaMalith/CVE-2015-4870⭐ 2 🔗 2 · Exploit
- https://bdu.fstec.ru/vul/2016-01117 · Security Note
- https://bdu.fstec.ru/vul/2016-00171 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3521 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2620 · Security Note
- https://bdu.fstec.ru/vul/2015-11860 · Security Note
- http://rhn.redhat.com/errata/RHSA-2016-2927.html · Vendor Advisory
- https://bdu.fstec.ru/vul/2015-11909 · Security Note
- https://bdu.fstec.ru/vul/2015-11918 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0644 · Security Note
- https://bdu.fstec.ru/vul/2016-01110 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4819 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5629 · Security Note