CVE-2019-2814
published 2019-07-23CVE-2019-2814: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to…
PriorityP48low2.2CVSS 3.1
AVNACHPRHUINSUCNILAN
EPSS
1.34%
68.0th percentile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 2.2 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | mysql | 8.0.0 – 8.0.16 | — |
| oracle_corporation | mysql_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | software_collections | — | — |
CVSS provenance
nvdv3.12.2LOWCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat2.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j6qp-fmgx-hf26: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB)
ghsa_unreviewed·2022-05-24
CVE-2019-2814 [LOW] GHSA-j6qp-fmgx-hf26: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 2.2 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).
Red Hat
mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
vendor_redhat·2019-07-16·CVSS 2.2
CVE-2019-2814 [LOW] mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 2.2 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Not affected
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
Package: mariadb (Red Hat Enterprise Linux 7) - Not affected
Package: mariadb:10.3/mar
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-2814 mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
bugzilla·2019-07-22·CVSS 2.2
CVE-2019-2814 [LOW] CVE-2019-2814 mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
CVE-2019-2814 mysql: InnoDB unspecified vulnerability (CPU Jul 2019)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data.
External References:
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Discussion:
Created community-mysql tracking bugs for this issue:
Affects: fedora-all [bug 1732044]
---
This issue has been addressed in the following products:
Red Hat Software Collections for Red Hat E
Bugzilla
CVE-2019-6283 libsass: heap-based buffer over-read in Sass::Prelexer::parenthese_scope in prelexer.hpp
bugzilla·2019-01-23·CVSS 6.5
CVE-2019-6283 [MEDIUM] CVE-2019-6283 libsass: heap-based buffer over-read in Sass::Prelexer::parenthese_scope in prelexer.hpp
CVE-2019-6283 libsass: heap-based buffer over-read in Sass::Prelexer::parenthese_scope in prelexer.hpp
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp.
References:
https://github.com/sass/libsass/issues/2814
Discussion:
Created libsass tracking bugs for this issue:
Affects: epel-7 [bug 1668920]
Affects: fedora-all [bug 1668919]
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://access.redhat.com/errata/RHSA-2019:2484https://access.redhat.com/errata/RHSA-2019:2511https://support.f5.com/csp/article/K10754336https://support.f5.com/csp/article/K10754336?utm_source=f5support&%3Butm_medium=RSShttp://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://access.redhat.com/errata/RHSA-2019:2484https://access.redhat.com/errata/RHSA-2019:2511https://support.f5.com/csp/article/K10754336https://support.f5.com/csp/article/K10754336?utm_source=f5support&%3Butm_medium=RSS
2019-07-23
Published