CVE-2018-3174

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H).
References
Link Resource
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Patch Vendor Advisory
http://www.securityfocus.com/bid/105612 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1041888 Broken Link Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2018:3655 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1258 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/11/msg00004.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/11/msg00007.html Mailing List Third Party Advisory
https://security.gentoo.org/glsa/201908-24 Third Party Advisory
https://security.netapp.com/advisory/ntap-20181018-0002/ Third Party Advisory
https://usn.ubuntu.com/3799-1/ Third Party Advisory
https://usn.ubuntu.com/3799-2/ Third Party Advisory
https://www.debian.org/security/2018/dsa-4341 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Patch Vendor Advisory
http://www.securityfocus.com/bid/105612 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1041888 Broken Link Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2018:3655 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1258 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/11/msg00004.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/11/msg00007.html Mailing List Third Party Advisory
https://security.gentoo.org/glsa/201908-24 Third Party Advisory
https://security.netapp.com/advisory/ntap-20181018-0002/ Third Party Advisory
https://usn.ubuntu.com/3799-1/ Third Party Advisory
https://usn.ubuntu.com/3799-2/ Third Party Advisory
https://www.debian.org/security/2018/dsa-4341 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-10-17 01:31

Updated : 2024-11-21 04:05


NVD link : CVE-2018-3174

Mitre link : CVE-2018-3174

CVE.ORG link : CVE-2018-3174


JSON object : View

Products Affected

netapp

  • active_iq_unified_manager
  • snapcenter
  • oncommand_workflow_automation
  • oncommand_insight

debian

  • debian_linux

oracle

  • mysql

mariadb

  • mariadb

canonical

  • ubuntu_linux