CVE-2016-0639Integer Overflow or Wraparound in Oracle Mysql

Severity
9.8CRITICALNVD
EPSS
15.3%
top 5.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 21
Latest updateMay 14

Description

Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Pluggable Authentication.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDoracle/mysql5.6.05.6.29+1

Also affects: Enterprise Linux 6.0, 7.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f26j-7rwf-2gmf: Unspecified vulnerability in Oracle MySQL 52022-05-14
OSV
CVE-2016-0639: Unspecified vulnerability in Oracle MySQL 52016-04-20

📋Vendor Advisories

3
Ubuntu
MySQL vulnerabilities2016-04-25
Red Hat
mysql: unspecified vulnerability in subcomponent: Server: Pluggable Authentication (CPU April 2016)2016-04-21
Ubuntu
MySQL vulnerabilities2016-04-21

🕵️Threat Intelligence

2
Qualys
Oracle Critical Patch Update April 2016 | Qualys2016-04-22
Qualys
Oracle Critical Patch Update April 2016 | Qualys2016-04-22

💬Community

1
Bugzilla
CVE-2016-0639 mysql: unspecified vulnerability in subcomponent: Server: Pluggable Authentication (CPU April 2016)2016-04-21