CVE-2018-3282Oracle Mysql vulnerability

36 documents7 sources
Severity
4.9MEDIUMNVD
EPSS
0.1%
top 67.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages8 packages

CVEListV5oracle_corporation/mysql_server4 versions+3
NVDoracle/mysql5.5.05.5.61+3
NVDmariadb/mariadb5.5.05.5.62+4
Alpinemariadb/mariadb< 10.3.11-r0+17

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hv5g-3886-rpxc: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines)2022-05-13
OSV
CVE-2018-3282: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines)2018-10-17
CVEList
CVE-2018-3282: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines)2018-10-17

📋Vendor Advisories

29
Ubuntu
MySQL vulnerabilities2018-10-29
Ubuntu
MySQL vulnerabilities2018-10-23
Red Hat
mysql: Server: Storage Engines unspecified vulnerability (CPU Oct 2018)2018-10-16
Red Hat
chromium-browser: Insufficient policy enforcement in Catalog Service2018-09-25
Red Hat
chromium-browser: Spoof of contents of the Omnibox (URL bar) via a crafted HTML page2018-09-25

💬Community

3
Bugzilla
CVE-2018-3282 mysql: Server: Storage Engines unspecified vulnerability (CPU Oct 2018)2018-10-17
Bugzilla
CVE-2018-6119 chromium-browser: Spoof of contents of the Omnibox (URL bar) via a crafted HTML page2018-09-26
Bugzilla
CVE-2018-6055 chromium-browser: Insufficient policy enforcement in Catalog Service2018-09-26
CVE-2018-3282 — Oracle Mysql vulnerability | cvebase