PT-2023-9675 · Oracle+2 · Mysql Server+1

Published

2023-12-07

·

Updated

2024-11-02

·

CVE-2024-21207

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MySQL Server versions 8.0.38 and prior MySQL Server versions 8.4.1 and prior MySQL Server versions 9.0.1 and prior
Description The issue is related to insufficient input validation in the InnoDB component of the MySQL Server. Exploitation of this issue can allow a remote attacker to cause a denial of service using the MySQL protocol. Successful attacks can result in the ability to cause the MySQL Server to hang or crash repeatedly, leading to a complete denial of service.
Recommendations For MySQL Server versions 8.0.38 and prior, update to a version that includes the fix for this issue. For MySQL Server versions 8.4.1 and prior, update to a version that includes the fix for this issue. For MySQL Server versions 9.0.1 and prior, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting network access to the MySQL Server to minimize the risk of exploitation.

Fix

DoS

Improper Resource Release

RCE

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2024-14481
ALT-PU-2024-14548
ALT-PU-2024-14706
ALT-PU-2024-14708
AZL-50396
AZL-50423
BDU:2024-09647
CVE-2024-21207
OESA-2024-2287

Affected Products

Alt Linux
Mysql Server