CVE-2019-2436

7 documents5 sources
Severity
5.5MEDIUM
EPSS
0.3%
top 42.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateMay 13

Description

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete acces

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:HExploitability: 1.2 | Impact: 4.2

Affected Packages4 packages

Also affects: Enterprise Linux 8.0, 8.1, 8.2, 8.4, 8.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cqrj-8533-q9mg: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication)2022-05-13
CVEList
CVE-2019-2436: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication)2019-01-16

📋Vendor Advisories

1
Red Hat
mysql: Server: Replication unspecified vulnerability (CPU Jan 2019)2019-01-15

💬Community

3
Bugzilla
CVE-2019-2420 CVE-2019-2434 CVE-2019-2436 CVE-2019-2455 CVE-2019-2481 CVE-2019-2482 CVE-2019-2486 CVE-2019-2494 CVE-2019-2495 CVE-2019-2502 CVE-2019-2503 CVE-2019-2507 CVE-2019-2510 CVE-2019-2528 ... 2019-01-16
Bugzilla
CVE-2019-2420 CVE-2019-2434 CVE-2019-2436 CVE-2019-2455 CVE-2019-2481 CVE-2019-2482 CVE-2019-2486 CVE-2019-2494 CVE-2019-2495 CVE-2019-2502 CVE-2019-2503 CVE-2019-2507 CVE-2019-2510 CVE-2019-2528 ... 2019-01-16
Bugzilla
CVE-2019-2436 mysql: Server: Replication unspecified vulnerability (CPU Jan 2019)2019-01-16