CVE-2019-2797Oracle Mysql vulnerability

8 documents7 sources
Severity
4.2MEDIUMNVD
EPSS
0.1%
top 65.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (c

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.5 | Impact: 3.6

Affected Packages3 packages

CVEListV5oracle_corporation/mysql_server5.7.26 and prior, 8.0.16 and prior+1
NVDoracle/mysql5.7.05.7.26+1

Also affects: Ubuntu Linux 16.04, 18.04, 19.04, Enterprise Linux 8.0, 8.1, 8.2, 8.4, 8.6

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m442-q7mg-f9r9: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs)2022-05-24
CVEList
CVE-2019-2797: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs)2019-07-23
OSV
CVE-2019-2797: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs)2019-07-19

📋Vendor Advisories

2
Ubuntu
MySQL vulnerabilities2019-07-24
Red Hat
mysql: Client programs unspecified vulnerability (CPU Jul 2019)2019-07-16

💬Community

2
Bugzilla
CVE-2019-2797 mysql: Client programs unspecified vulnerability (CPU Jul 2019)2019-07-22
Bugzilla
CVE-2019-2731 CVE-2019-2737 CVE-2019-2738 CVE-2019-2739 CVE-2019-2740 CVE-2019-2755 CVE-2019-2757 CVE-2019-2758 CVE-2019-2774 CVE-2019-2778 CVE-2019-2797 CVE-2019-2805 CVE-2019-2819 mysql:5.7/communit2019-07-22
CVE-2019-2797 — Oracle Mysql vulnerability | cvebase