Vulnerability CVE-2015-4870


Published: 2015-10-21   Modified: 2015-10-23

Description:
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
MySQL 5.5.45 - procedure analyse Function Denial of Service
Osanda Malith
30.05.2016

Type:

CWE-noinfo

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Redhat -> Enterprise linux desktop 
Redhat -> Enterprise linux hpc node 
Redhat -> Enterprise linux hpc node eus 
Redhat -> Enterprise linux server 
Redhat -> Enterprise linux server aus 
Redhat -> Enterprise linux server eus 
Redhat -> Enterprise linux workstation 
Redhat -> Enterprise linux 
Oracle -> Solaris 
Oracle -> Mysql 
Oracle -> Linux 
Opensuse -> LEAP 
Novell -> LEAP 
Novell -> Suse linux enterprise desktop 
Novell -> Suse linux enterprise server 
Novell -> Suse linux enterprise software development kit 
Novell -> Suse linux enterprise workstation extension 

 References:
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177539.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00011.html
http://lists.opensuse.org/opensuse-updates/2016-02/msg00039.html
http://packetstormsecurity.com/files/137232/MySQL-Procedure-Analyse-Denial-Of-Service.html
http://rhn.redhat.com/errata/RHSA-2016-0534.html
http://rhn.redhat.com/errata/RHSA-2016-0705.html
http://rhn.redhat.com/errata/RHSA-2016-1480.html
http://rhn.redhat.com/errata/RHSA-2016-1481.html
http://www.debian.org/security/2015/dsa-3377
http://www.debian.org/security/2015/dsa-3385
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
http://www.securityfocus.com/bid/77208
http://www.securitytracker.com/id/1033894
http://www.ubuntu.com/usn/USN-2781-1
https://access.redhat.com/errata/RHSA-2016:1132
https://www.exploit-db.com/exploits/39867/
https://www.suse.com/support/update/announcement/2016/suse-su-20160296-1.html

Copyright 2024, cxsecurity.com

 

Back to Top