CVE-2013-3801
published 2013-07-17CVE-2013-3801: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.79%
88.8th percentile
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mariadb | mariadb | >= 10.0.0 < 10.0.3 | 10.0.3 |
| mariadb | mariadb | >= 5.5.0 < 5.5.31 | 5.5.31 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | mysql | 5.5.0 – 5.5.30 | — |
| oracle | mysql | 5.6.0 – 5.6.10 | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Heat template URL information leakage
ghsa·2022-05-14
CVE-2014-3801 [LOW] CWE-200 OpenStack Heat template URL information leakage
OpenStack Heat template URL information leakage
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
GHSA
GHSA-vvp5-hx8c-5hqm: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-13
CVE-2013-3801 [MEDIUM] GHSA-vvp5-hx8c-5hqm: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
Red Hat
openstack-heat: authenticated information leak in Heat
vendor_redhat·2014-04-23·CVSS 3.5
CVE-2014-3801 [LOW] CWE-200 openstack-heat: authenticated information leak in Heat
openstack-heat: authenticated information leak in Heat
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
It was discovered that a user could temporarily be able to see the URL of a provider template used in another tenant. If the template itself could be accessed, then additional information could be leaked that would otherwise not be visible.
Package: openstack-heat (Red Hat OpenStack Platform 3) - Will not fix
Red Hat
mysql: unspecified DoS related to Server Options (CPU July 2013)
vendor_redhat·2013-07-17·CVSS 5.0
CVE-2013-3801 [MEDIUM] mysql: unspecified DoS related to Server Options (CPU July 2013)
mysql: unspecified DoS related to Server Options (CPU July 2013)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
Statement: Not vulnerable. This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 5 and 6.
Package: mysql (Red Hat Enterprise Linux 5) - Not affected
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3801 openstack-heat: authenticated information leak in Heat
bugzilla·2014-05-21·CVSS 3.5
CVE-2014-3801 [LOW] CVE-2014-3801 openstack-heat: authenticated information leak in Heat
CVE-2014-3801 openstack-heat: authenticated information leak in Heat
Title: Heat template URL information leakage
Reporter: Jason Dunsmore (Rackspace)
Products: Heat
Versions: 2013.2 to 2013.2.3, and 2014.1
Description:
Jason Dunsmore from Rackspace reported a vulnerability in Heat. An
authenticated user may temporarily see the URL of a provider template
used in another tenant by listing heat resources types. This may result
in disclosure of additional information if the template itself can be
accessed. The URL disappears from the listing after a certain point in
the stack creation. All Heat setups are affected.
https://launchpad.net/bugs/1311223
http://seclists.org/oss-sec/2014/q2/338
Discussion:
Created openstack-heat tracking bugs for this issue:
Affects: fedora-all [bug 1099749]
Bugzilla
CVE-2013-3801 mysql: unspecified DoS related to Server Options (CPU July 2013)
bugzilla·2013-07-18·CVSS 5.0
CVE-2013-3801 [MEDIUM] CVE-2013-3801 mysql: unspecified DoS related to Server Options (CPU July 2013)
CVE-2013-3801 mysql: unspecified DoS related to Server Options (CPU July 2013)
Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users
to affect availability via unknown vectors related to Server Options.
External References:
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html#AppendixMSQL
Discussion:
Statement:
Not vulnerable. This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 5 and 6.
---
This issue has been addressed in Fedora-18 (mysql) and Fedora-19 (community-mysql) via the following security updates:
https://admin.fedoraproject.org/updates/FEDORA-2013-11108/mysql-5.5.32-1.fc18
https://admin.fedoraproject.org/updates/FEDORA-2013-10852/c
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2013-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00008.htmlhttp://osvdb.org/95331http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.securityfocus.com/bid/61269http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2013-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00008.htmlhttp://osvdb.org/95331http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.securityfocus.com/bid/61269
2013-07-17
Published