Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-22084

Опубликовано: 17 окт. 2023
Источник: debian
EPSS Низкий

Описание

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43 and prior, 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mariadbfixed1:10.11.6-1package
mariadbfixed1:10.11.6-0+deb12u1bookwormpackage
mariadb-10.5removedpackage
mariadb-10.5fixed1:10.5.23-0+deb11u1bullseyepackage
mariadb-10.3removedpackage
mysql-8.0fixed8.0.35-1package

Примечания

  • Fixed in MariaDB: 11.2.2, 11.1.3, 11.0.4, 10.11.6, 10.10.7, 10.6.16, 10.5.23, 10.4.32

  • https://github.com/MariaDB/server/commit/15ae97b1c2c14f1263cdc853673c4129625323de (mariadb-10.4.32)

  • MariaDB bug: https://jira.mariadb.org/browse/MDEV-32578

  • MySQL commit: https://github.com/mysql/mysql-server/commit/38e9a0779aeea2d197c727e306a910c56b26a47c (mysql-5.7.44)

  • Introduced by MySQL commit: https://github.com/mysql/mysql-server/commit/0c954c2289a75d90d1088356b1092437ebf45a1d (mysql-5.7.2-12)

EPSS

Процентиль: 80%
0.01482
Низкий

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 1 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43 and prior, 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
redhat
больше 1 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43 and prior, 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
nvd
больше 1 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43 and prior, 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
msrc
больше 1 года назад

Описание отсутствует

suse-cvrf
около 1 года назад

Security update for mariadb104

EPSS

Процентиль: 80%
0.01482
Низкий