CVE-2018-3081

Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client as well as unauthorized update, insert or delete access to some of MySQL Client accessible data. CVSS 3.0 Base Score 5.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H).
References
Link Resource
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Patch Vendor Advisory
http://www.securityfocus.com/bid/104779 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1041294 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2018:3655 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1258 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2327 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/11/msg00004.html Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20180726-0002/ Third Party Advisory
https://usn.ubuntu.com/3725-1/ Third Party Advisory
https://usn.ubuntu.com/3725-2/ Third Party Advisory
https://www.debian.org/security/2018/dsa-4341 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Patch Vendor Advisory
http://www.securityfocus.com/bid/104779 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1041294 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2018:3655 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1258 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2327 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/11/msg00004.html Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20180726-0002/ Third Party Advisory
https://usn.ubuntu.com/3725-1/ Third Party Advisory
https://usn.ubuntu.com/3725-2/ Third Party Advisory
https://www.debian.org/security/2018/dsa-4341 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-18 13:29

Updated : 2024-11-21 04:05


NVD link : CVE-2018-3081

Mitre link : CVE-2018-3081

CVE.ORG link : CVE-2018-3081


JSON object : View

Products Affected

redhat

  • enterprise_linux_workstation
  • enterprise_linux_desktop
  • enterprise_linux_server

netapp

  • storage_automation_store
  • snapcenter
  • oncommand_workflow_automation
  • oncommand_insight

debian

  • debian_linux

oracle

  • mysql

mariadb

  • mariadb

canonical

  • ubuntu_linux