CVE-2019-2537
published 2019-01-16CVE-2019-2537: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and…
PriorityP423medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
4.42%
90.3th percentile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 0 < 10.1.38-r0 | 10.1.38-r0 |
| mariadb | mariadb | >= 0 < 10.1.38-r0 | 10.1.38-r0 |
| mariadb | mariadb | >= 0 < 10.2.22.r0 | 10.2.22.r0 |
| mariadb | mariadb | >= 0 < 10.3.13-r0 | 10.3.13-r0 |
| mariadb | mariadb | >= 10.0.0 < 10.0.38 | 10.0.38 |
| mariadb | mariadb | >= 10.1.0 < 10.1.38 | 10.1.38 |
| mariadb | mariadb | >= 10.2.0 < 10.2.22 | 10.2.22 |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cxvc-c563-9w9g: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL)
ghsa_unreviewed·2022-05-13
CVE-2019-2537 [MEDIUM] GHSA-cxvc-c563-9w9g: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
OSV
CVE-2019-2537: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL)
osv·2019-01-16·CVSS 4.9
CVE-2019-2537 [MEDIUM] CVE-2019-2537: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2019-01-23
CVE-2019-2420 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
a new upstream MySQL version to fix these issues.
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10 have been updated to
MySQL 5.7.25.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-25.html
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
vendor_redhat·2019-01-15·CVSS 4.9
CVE-2019-2537 [MEDIUM] mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Out of support scope
Package: mysql (Red Hat Enterprise Linux 6) - Out of support scope
Package
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11777 org.eclipse.paho.client.mqttv3: Improper hostname validation in the MQTT library
bugzilla·2020-09-16·CVSS 7.5
CVE-2019-11777 [HIGH] CVE-2019-11777 org.eclipse.paho.client.mqttv3: Improper hostname validation in the MQTT library
CVE-2019-11777 org.eclipse.paho.client.mqttv3: Improper hostname validation in the MQTT library
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information.
Upstream bug:
https://bugs.eclipse.org/bugs/show_bug.cgi?id=549934
Upstream issue:
https://github.com/eclipse/paho.mqtt.java/issues/506
Upstream patch:
https://github.com/CVEProject/cvelist/pull/2537
Discussion:
This vulnerability is out of security support scope for the following product:
* Red Hat JBoss Fuse 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for mor
Bugzilla
mariadb: mysql: Server: DDL unspecified vulnerability (CPU Jan 2019) [fedora-29]
bugzilla·2019-04-09·CVSS 4.9
[MEDIUM] mariadb: mysql: Server: DDL unspecified vulnerability (CPU Jan 2019) [fedora-29]
mariadb: mysql: Server: DDL unspecified vulnerability (CPU Jan 2019) [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the
Bugzilla
mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
bugzilla·2019-04-09·CVSS 4.9
[MEDIUM] mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Discussion:
Created community-mysql tracking bugs for this issue:
Affects: fedora-28 [bug 1698122]
Affects: fedora-29 [bug 1698125]
Created mariadb tracking
Bugzilla
CVE-2019-2420 CVE-2019-2434 CVE-2019-2455 CVE-2019-2481 CVE-2019-2482 CVE-2019-2486 CVE-2019-2503 CVE-2019-2507 CVE-2019-2510 CVE-2019-2528 CVE-2019-2529 CVE-2019-2531 CVE-2019-2532 CVE-2019-2534 CVE-
bugzilla·2019-01-16·CVSS 4.9
CVE-2019-2420 [MEDIUM] CVE-2019-2420 CVE-2019-2434 CVE-2019-2455 CVE-2019-2481 CVE-2019-2482 CVE-2019-2486 CVE-2019-2503 CVE-2019-2507 CVE-2019-2510 CVE-2019-2528 CVE-2019-2529 CVE-2019-2531 CVE-2019-2532 CVE-2019-2534 CVE-
CVE-2019-2420 CVE-2019-2434 CVE-2019-2455 CVE-2019-2481 CVE-2019-2482 CVE-2019-2486 CVE-2019-2503 CVE-2019-2507 CVE-2019-2510 CVE-2019-2528 CVE-2019-2529 CVE-2019-2531 CVE-2019-2532 CVE-2019-2534 CVE-2019-2537 community-mysql: various flaws [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relev
Bugzilla
CVE-2019-2537 mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
bugzilla·2019-01-16·CVSS 4.9
CVE-2019-2537 [MEDIUM] CVE-2019-2537 mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
CVE-2019-2537 mysql: Server: DDL unspecified vulnerability (CPU Jan 2019)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
http://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Discussion:
Created community-mysql tracking bugs for this issue:
Affects: fedora-28 [bug 1666776]
Affects: fedora-29 [bug 1666778]
Created mys
Bugzilla
CVE-2019-2455 CVE-2019-2481 CVE-2019-2482 CVE-2019-2503 CVE-2019-2507 CVE-2019-2529 CVE-2019-2531 CVE-2019-2534 CVE-2019-2537 mysql:5.6/community-mysql: various flaws [fedora-28]
bugzilla·2019-01-16·CVSS 6.5
CVE-2019-2455 [MEDIUM] CVE-2019-2455 CVE-2019-2481 CVE-2019-2482 CVE-2019-2503 CVE-2019-2507 CVE-2019-2529 CVE-2019-2531 CVE-2019-2534 CVE-2019-2537 mysql:5.6/community-mysql: various flaws [fedora-28]
CVE-2019-2455 CVE-2019-2481 CVE-2019-2482 CVE-2019-2503 CVE-2019-2507 CVE-2019-2529 CVE-2019-2531 CVE-2019-2534 CVE-2019-2537 mysql:5.6/community-mysql: various flaws [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in th
http://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttp://www.securityfocus.com/bid/106619https://access.redhat.com/errata/RHSA-2019:1258https://access.redhat.com/errata/RHSA-2019:2484https://access.redhat.com/errata/RHSA-2019:2511https://access.redhat.com/errata/RHSA-2019:3708https://lists.debian.org/debian-lts-announce/2019/02/msg00000.htmlhttps://security.gentoo.org/glsa/201908-24https://security.netapp.com/advisory/ntap-20190118-0002/https://usn.ubuntu.com/3867-1/http://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttp://www.securityfocus.com/bid/106619https://access.redhat.com/errata/RHSA-2019:1258https://access.redhat.com/errata/RHSA-2019:2484https://access.redhat.com/errata/RHSA-2019:2511https://access.redhat.com/errata/RHSA-2019:3708https://lists.debian.org/debian-lts-announce/2019/02/msg00000.htmlhttps://security.gentoo.org/glsa/201908-24https://security.netapp.com/advisory/ntap-20190118-0002/https://usn.ubuntu.com/3867-1/
2019-01-16
Published