CVE-2019-2815
published 2019-07-23CVE-2019-2815: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior…
PriorityP421medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
2.01%
78.8th percentile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | mysql | 8.0.0 – 8.0.16 | — |
| oracle_corporation | mysql_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | software_collections | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gv2v-72f9-437h: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer)
ghsa_unreviewed·2022-05-24
CVE-2019-2815 [MEDIUM] GHSA-gv2v-72f9-437h: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Red Hat
mysql: Server: Optimizer unspecified vulnerability (CPU Jul 2019)
vendor_redhat·2019-07-16·CVSS 4.9
CVE-2019-2815 [MEDIUM] mysql: Server: Optimizer unspecified vulnerability (CPU Jul 2019)
mysql: Server: Optimizer unspecified vulnerability (CPU Jul 2019)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Not affected
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
Package: mariadb (Red Hat Enterprise Linux 7) - No
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-2815 mysql: Server: Optimizer unspecified vulnerability (CPU Jul 2019)
bugzilla·2019-07-22·CVSS 4.9
CVE-2019-2815 [MEDIUM] CVE-2019-2815 mysql: Server: Optimizer unspecified vulnerability (CPU Jul 2019)
CVE-2019-2815 mysql: Server: Optimizer unspecified vulnerability (CPU Jul 2019)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Discussion:
Created community-mysql tracking bugs for this issue:
Affects: fedora-all [bug 1732044]
---
This issue has been addressed in the following products:
Red Hat
Bugzilla
CVE-2019-6286 libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp
bugzilla·2019-01-23·CVSS 8.1
CVE-2019-6286 [HIGH] CVE-2019-6286 libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp
CVE-2019-6286 libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.
References:
https://github.com/sass/libsass/issues/2815
Discussion:
Created libsass tracking bugs for this issue:
Affects: epel-7 [bug 1668926]
Affects: fedora-all [bug 1668925]
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://access.redhat.com/errata/RHSA-2019:2484https://access.redhat.com/errata/RHSA-2019:2511https://support.f5.com/csp/article/K02585438https://support.f5.com/csp/article/K02585438?utm_source=f5support&%3Butm_medium=RSShttp://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://access.redhat.com/errata/RHSA-2019:2484https://access.redhat.com/errata/RHSA-2019:2511https://support.f5.com/csp/article/K02585438https://support.f5.com/csp/article/K02585438?utm_source=f5support&%3Butm_medium=RSS
2019-07-23
Published