CVE
CVE-2018-2846
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Performance Schema). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
- Severity
- MEDIUM
- CVSS
- 4.9
- Published
- Modified
Linked Releases
| Distribution | Release | Status | Evidence |
|---|---|---|---|
| Ubuntu | 18.04.6 amd64 desktop | unknown | source |
| Ubuntu | 18.04.6 amd64 live-server | unknown | source |
| Ubuntu | 16.04.7 amd64 desktop | unknown | source |
| Ubuntu | 16.04.6 i386 desktop | unknown | source |
| Ubuntu | 16.04.7 amd64 server | unknown | source |
| Ubuntu | 16.04.6 i386 server | unknown | source |
| Ubuntu | 14.04.6 amd64 desktop | unknown | source |
| Ubuntu | 14.04.6 i386 desktop | unknown | source |
| Ubuntu | 14.04.6 amd64 server | unknown | source |
| Ubuntu | 14.04.6 i386 server | unknown | source |
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.securityfocus.com/bid/103790
- http://www.securitytracker.com/id/1040698
- https://access.redhat.com/errata/RHSA-2018:3655
- https://security.netapp.com/advisory/ntap-20180419-0002/
- https://usn.ubuntu.com/3629-1/
- https://usn.ubuntu.com/3629-3/
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.securityfocus.com/bid/103790
- http://www.securitytracker.com/id/1040698
- https://access.redhat.com/errata/RHSA-2018:3655
- https://security.netapp.com/advisory/ntap-20180419-0002/
- https://usn.ubuntu.com/3629-1/
- https://usn.ubuntu.com/3629-3/