CVE-2019-2920
published 2019-10-16CVE-2019-2920: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 5.3.13 and prior and 8.0.17…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
2.25%
80.9th percentile
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 5.3.13 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| oracle | mysql | 5.3.0 – 5.3.13 | — |
| oracle | mysql | 8.0.0 – 8.0.17 | — |
| oracle_corporation | mysql_connectors | — | — |
| oracle_corporation | mysql_connectors | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c2q7-fc95-57p5: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)
ghsa_unreviewed·2022-05-24
CVE-2019-2920 [MEDIUM] GHSA-c2q7-fc95-57p5: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 5.3.13 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
OSV
CVE-2019-2920: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)
osv·2019-10-16·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 5.3.13 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Red Hat
mysql-connector-odbc: An unauthenticated attacker with network access can, via multiple protocols compromise MySQL Connectors
vendor_redhat·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CWE-863 mysql-connector-odbc: An unauthenticated attacker with network access can, via multiple protocols compromise MySQL Connectors
mysql-connector-odbc: An unauthenticated attacker with network access can, via multiple protocols compromise MySQL Connectors
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 5.3.13 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Package: mysql-connector-odbc (Red Hat Enterprise Linux 5) - Out of support scope
Package: mysql-connec
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2019-11-18
CVE-2019-2910 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 8.0.18 in Ubuntu 19.10. Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 19.04 have been updated to MySQL 5.7.28.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-28.html
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html
https://www.oracle.com/security-alerts/cpuoct2019.html
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In ge
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-2920 mysql-connector-odbc: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
bugzilla·2019-11-20·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 mysql-connector-odbc: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
CVE-2019-2920 mysql-connector-odbc: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM
Bugzilla
CVE-2019-2920 mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
bugzilla·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
CVE-2019-2920 mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
Bugzilla
CVE-2019-2920 mariadb:10.1/mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-29]
bugzilla·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 mariadb:10.1/mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-29]
CVE-2019-2920 mariadb:10.1/mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM ch
Bugzilla
CVE-2019-2920 mysql:5.6/community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-30]
bugzilla·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 mysql:5.6/community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-30]
CVE-2019-2920 mysql:5.6/community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the R
Bugzilla
CVE-2019-2920 mariadb:10.4/mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
bugzilla·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 mariadb:10.4/mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
CVE-2019-2920 mariadb:10.4/mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM
Bugzilla
CVE-2019-2920 community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
bugzilla·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
CVE-2019-2920 community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chang
Bugzilla
CVE-2019-2920 mariadb:10.3/mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
bugzilla·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 mariadb:10.3/mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
CVE-2019-2920 mariadb:10.3/mariadb: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM
Bugzilla
CVE-2019-2920 mysql-connector-odbc: An unauthenticated attacker with network access can, via multiple protocols compromise MySQL Connectors
bugzilla·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 mysql-connector-odbc: An unauthenticated attacker with network access can, via multiple protocols compromise MySQL Connectors
CVE-2019-2920 mysql-connector-odbc: An unauthenticated attacker with network access can, via multiple protocols compromise MySQL Connectors
An unauthenticated attacker with network access can, via multiple protocols compromise MySQL Connectors. Successful attacks of this vulnerability can result in a partial denial of service of MySQL Connectors.
Affected versions are 5.3.13 and prior and 8.0.17 and prior.
Discussion:
Created community-mysql tracking bugs for this issue:
Affects: fedora-all [bug 1774056]
Created mariadb tracking bugs for this issue:
Affects: fedora-all [bug 1774050]
Created mariadb:10.1/mariadb tracking bugs for this issue:
Affects: fedora-29 [bug 1774053]
Created mariadb:10.3/mariadb tracking bugs for this issue:
Affects: fedora-all [bug 1774051]
Created ma
Bugzilla
CVE-2019-2920 mysql:8.0/community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
bugzilla·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 mysql:8.0/community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
CVE-2019-2920 mysql:8.0/community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the
Bugzilla
CVE-2019-2920 mysql:5.7/community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
bugzilla·2019-11-19·CVSS 5.3
CVE-2019-2920 [MEDIUM] CVE-2019-2920 mysql:5.7/community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
CVE-2019-2920 mysql:5.7/community-mysql: mysql: Connector: unauthenticated attacker can via multiple protocols compromise MySQL Connectors leading to a partial DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the
2019-10-16
Published