CVE-2019-2798
published 2019-07-23CVE-2019-2798: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily…
PriorityP421medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
2.01%
78.8th percentile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | mysql | 8.0.0 – 8.0.16 | — |
| oracle_corporation | mysql_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | software_collections | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m9j3-qxhm-3f65: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB)
ghsa_unreviewed·2022-05-24
CVE-2019-2798 [MEDIUM] GHSA-m9j3-qxhm-3f65: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Red Hat
mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
vendor_redhat·2019-07-16·CVSS 4.9
CVE-2019-2798 [MEDIUM] mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Not affected
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
Package: mariadb (Red Hat Enterprise Linux 7) - Not affected
Package: m
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20969 patch: do_ed_script in pch.c does not block strings beginning with a ! character
bugzilla·2019-08-29·CVSS 7.8
CVE-2018-20969 [HIGH] CVE-2018-20969 patch: do_ed_script in pch.c does not block strings beginning with a ! character
CVE-2018-20969 patch: do_ed_script in pch.c does not block strings beginning with a ! character
A vulnerability was found in do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.
Reference:
https://git.savannah.gnu.org/cgit/patch.git/commit/?id=3fcd042d26d70856e826a42b5f93dc4854d80bf0
https://seclists.org/bugtraq/2019/Aug/29
Discussion:
Created patch tracking bugs for this issue:
Affects: fedora-all [bug 1746673]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2798 https://access.redhat.com/errata/RHSA-2019:2798
---
This bug is now closed. Further u
Bugzilla
CVE-2019-2798 mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
bugzilla·2019-07-22·CVSS 4.9
CVE-2019-2798 [MEDIUM] CVE-2019-2798 mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
CVE-2019-2798 mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Discussion:
Created community-mysql tracking bugs for this issue:
Affects: fedora-all [bug 1732044]
---
This issue has been addressed in the following products:
Red Hat Software Collections f
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://access.redhat.com/errata/RHSA-2019:2484https://access.redhat.com/errata/RHSA-2019:2511https://support.f5.com/csp/article/K23125024https://support.f5.com/csp/article/K23125024?utm_source=f5support&%3Butm_medium=RSShttp://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://access.redhat.com/errata/RHSA-2019:2484https://access.redhat.com/errata/RHSA-2019:2511https://support.f5.com/csp/article/K23125024https://support.f5.com/csp/article/K23125024?utm_source=f5support&%3Butm_medium=RSS
2019-07-23
Published