PT-2018-3025 · Mysql Server +6 · Mysql Server +6
Published
2018-04-17
·
Updated
2023-12-29
·
CVE-2018-2819
6.8
Medium
Base vector | Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
MySQL Server versions 5.5.59 and prior
MySQL Server versions 5.6.39 and prior
MySQL Server versions 5.7.21 and prior
Description:
The issue is related to the InnoDB component of the MySQL Server, which can be exploited by an attacker with network access via multiple protocols. This can result in the ability to cause a hang or frequently repeatable crash of the MySQL Server, leading to a denial of service. The vulnerability is easily exploitable and can be used by a low-privileged attacker.
Recommendations:
For MySQL Server version 5.5.59 and prior, update to a version later than 5.5.59 to resolve the issue.
For MySQL Server version 5.6.39 and prior, update to a version later than 5.6.39 to resolve the issue.
For MySQL Server version 5.7.21 and prior, update to a version later than 5.7.21 to resolve the issue.
As a temporary workaround, consider restricting network access to the MySQL Server to minimize the risk of exploitation.
Fix
Improper Resource Release
Weakness Enumeration
Related Identifiers
Affected Products
References · 702
- https://ubuntu.com/security/CVE-2018-2846 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2781 · Security Note
- https://bdu.fstec.ru/vul/2019-03454 · Security Note
- https://osv.dev/vulnerability/SUSE-SU-2018:1382-1 · Vendor Advisory
- https://bdu.fstec.ru/vul/2020-00680 · Security Note
- https://ubuntu.com/security/CVE-2018-2813 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3064 · Security Note
- https://advisories.mageia.org/MGASA-2018-0259.html · Security Note
- https://ubuntu.com/security/CVE-2018-2766 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14550 · Security Note
- https://osv.dev/vulnerability/SUSE-SU-2018:1333-1 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3313 · Security Note
- https://bdu.fstec.ru/vul/2019-03456 · Security Note
- https://access.redhat.com/errata/RHSA-2018:2729 · Vendor Advisory
- https://bdu.fstec.ru/vul/2019-00448 · Security Note