PT-2018-16029 · Oracle+6 · Mysql Server+6

Published

2018-06-04

·

Updated

2023-10-21

·

CVE-2018-3081

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.5.60 and prior Oracle MySQL versions 5.6.40 and prior Oracle MySQL versions 5.7.22 and prior Oracle MySQL versions 8.0.11 and prior
Description The issue allows a high privileged attacker with network access via multiple protocols to compromise the MySQL Client. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash of the MySQL Client, as well as unauthorized update, insert, or delete access to some of the MySQL Client accessible data.
Recommendations For versions 5.5.60 and prior, update to a version later than 5.5.60 to resolve the issue. For versions 5.6.40 and prior, update to a version later than 5.6.40 to resolve the issue. For versions 5.7.22 and prior, update to a version later than 5.7.22 to resolve the issue. For versions 8.0.11 and prior, update to a version later than 8.0.11 to resolve the issue.

Fix

Related Identifiers

ALT-PU-2018-1842
ALT-PU-2018-2267
CESA-2019_2327
CVE-2018-3081
DLA-1407-1
DLA-1566-1
DSA-4341-1
OPENSUSE-SU-2018_2293-1
RHSA-2018:3655
RHSA-2019:1258
RHSA-2019:2327
RHSA-2019_2327
ROSA-SA-2023-2251
SUSE-SU-2018:2411-1
USN-3725-1
USN-3725-2

Affected Products

Alt Linux
Centos
Mariadb Server
Mysql Server
Red Hat
Suse
Ubuntu