CVE-2013-0371
published 2013-01-17CVE-2013-0371: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to…
PriorityP416medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.55%
83.2th percentile
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mariadb | mariadb | — | — |
| mariadb | mariadb | >= 5.5.0 < 5.5.29 | 5.5.29 |
| oracle | mysql | 5.5.0 – 5.5.28 | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2013-01-22
CVE-2012-0572 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 5.1.67 in Ubuntu 10.04 LTS and Ubuntu 11.10.
Ubuntu 12.04 LTS and Ubuntu 12.10 have been updated to MySQL 5.5.29.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-67.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-29.html
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Instructions: In general, a standard system update will make all the necessary
Red Hat
mysql: unspecified DoS vulnerability related to MyISAM (CPU Jan 2013)
vendor_redhat·2013-01-15·CVSS 4.0
CVE-2013-0371 [MEDIUM] mysql: unspecified DoS vulnerability related to MyISAM (CPU Jan 2013)
mysql: unspecified DoS vulnerability related to MyISAM (CPU Jan 2013)
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.
Statement: Not vulnerable. Upstream notes this issue only affected MySQL 5.5.x. Red Hat Enterprise Linux 5 and 6 include MySQL versions 5.0.x and 5.1.x respectively, which are not listed as affected.
Package: mysql (Red Hat Enterprise Linux 5) - Not affected
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-pmg6-ppww-gp2c: Unspecified vulnerability in the Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-05
CVE-2013-0371 [MEDIUM] GHSA-pmg6-ppww-gp2c: Unspecified vulnerability in the Server component in Oracle MySQL 5
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6468 Drools: Remote Java Code Execution in MVEL
bugzilla·2014-01-09·CVSS 6.5
CVE-2013-6468 [MEDIUM] CVE-2013-6468 Drools: Remote Java Code Execution in MVEL
CVE-2013-6468 Drools: Remote Java Code Execution in MVEL
A code execution vulnerability has been discovered in Drools. The flaw allows remote authenticated attackers to submit arbitrary Java code in MVEL or Drools expressions, the code would be executed within the security context of the application server.
Discussion:
This issue has been addressed in following products:
Red Hat JBoss BPM Suite 6.0.1
Via RHSA-2014:0371 https://rhn.redhat.com/errata/RHSA-2014-0371.html
---
This issue has been addressed in following products:
Red Hat JBoss BRMS 6.0.1
Via RHSA-2014:0372 https://rhn.redhat.com/errata/RHSA-2014-0372.html
Bugzilla
CVE-2013-0371 mysql: unspecified DoS vulnerability related to MyISAM (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 4.0
CVE-2013-0371 [MEDIUM] CVE-2013-0371 mysql: unspecified DoS vulnerability related to MyISAM (CPU Jan 2013)
CVE-2013-0371 mysql: unspecified DoS vulnerability related to MyISAM (CPU Jan 2013)
An unspecified vulnerability in the MyISAM subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote authenticated attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
Text of the Oracle flaw description:
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM). Supported versions that are affected are 5.5.28 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash
http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.htmlhttp://www.ubuntu.com/usn/USN-1703-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16451http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.htmlhttp://www.ubuntu.com/usn/USN-1703-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16451
2013-01-17
Published