CVE-2019-2923
published 2019-10-16CVE-2019-2923: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.29%
81.4th percentile
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| oracle | mysql | 5.6.0 – 5.6.45 | — |
| oracle | mysql | 5.7.0 – 5.7.27 | — |
| oracle_corporation | mysql_server | — | — |
| oracle_corporation | mysql_server | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2019-11-18
CVE-2019-2910 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 8.0.18 in Ubuntu 19.10. Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 19.04 have been updated to MySQL 5.7.28.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-28.html
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html
https://www.oracle.com/security-alerts/cpuoct2019.html
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In ge
Red Hat
mysql: Server: Security: Encryption unspecified vulnerability (CPU Oct 2019)
vendor_redhat·2019-10-15·CVSS 5.3
CVE-2019-2923 [MEDIUM] mysql: Server: Security: Encryption unspecified vulnerability (CPU Oct 2019)
mysql: Server: Security: Encryption unspecified vulnerability (CPU Oct 2019)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Out of support scope
Package: mysql (Red Hat Enterprise Linux 6) - Out of support scope
Package: mariadb (Red H
GHSA
GHSA-873v-pm99-33mp: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption)
ghsa_unreviewed·2022-05-24
CVE-2019-2923 [MEDIUM] GHSA-873v-pm99-33mp: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
OSV
CVE-2019-2923: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption)
osv·2019-10-16·CVSS 5.3
CVE-2019-2923 [MEDIUM] CVE-2019-2923: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20892 net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request
bugzilla·2020-06-25·CVSS 6.5
CVE-2019-20892 [MEDIUM] CVE-2019-20892 net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request
CVE-2019-20892 net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.
References:
https://sourceforge.net/p/net-snmp/bugs/2923/
https://bugzilla.redhat.com/show_bug.cgi?id=1663027
Upstream commit:
https://github.com/net-snmp/net-snmp/commit/5f881d3bf24599b90d67a45cae7a3eb099cd71c9
Discussion:
Created net-snmp tracking bugs for this issue:
Affects: fedora-all [bug 1851150]
---
This issue has been addressed in Red Hat Enterprise Linux 8 via:
https://access.redhat.com/erra
Bugzilla
CVE-2019-2910 CVE-2019-2911 CVE-2019-2922 CVE-2019-2923 CVE-2019-2924 CVE-2019-2974 mysql:5.6/community-mysql: various flaws [fedora-30]
bugzilla·2019-11-03·CVSS 3.7
CVE-2019-2910 [LOW] CVE-2019-2910 CVE-2019-2911 CVE-2019-2922 CVE-2019-2923 CVE-2019-2924 CVE-2019-2974 mysql:5.6/community-mysql: various flaws [fedora-30]
CVE-2019-2910 CVE-2019-2911 CVE-2019-2922 CVE-2019-2923 CVE-2019-2924 CVE-2019-2974 mysql:5.6/community-mysql: various flaws [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mess
Bugzilla
CVE-2019-2910 CVE-2019-2911 CVE-2019-2914 CVE-2019-2922 CVE-2019-2923 CVE-2019-2924 CVE-2019-2938 CVE-2019-2946 CVE-2019-2960 CVE-2019-2974 CVE-2019-2993 mysql:5.7/community-mysql: various flaws [fedo
bugzilla·2019-11-03·CVSS 3.7
CVE-2019-2910 [LOW] CVE-2019-2910 CVE-2019-2911 CVE-2019-2914 CVE-2019-2922 CVE-2019-2923 CVE-2019-2924 CVE-2019-2938 CVE-2019-2946 CVE-2019-2960 CVE-2019-2974 CVE-2019-2993 mysql:5.7/community-mysql: various flaws [fedo
CVE-2019-2910 CVE-2019-2911 CVE-2019-2914 CVE-2019-2922 CVE-2019-2923 CVE-2019-2924 CVE-2019-2938 CVE-2019-2946 CVE-2019-2960 CVE-2019-2974 CVE-2019-2993 mysql:5.7/community-mysql: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention
Bugzilla
CVE-2019-2923 mysql: Server: Security: Encryption unspecified vulnerability (CPU Oct 2019)
bugzilla·2019-10-23·CVSS 5.3
CVE-2019-2923 [MEDIUM] CVE-2019-2923 mysql: Server: Security: Encryption unspecified vulnerability (CPU Oct 2019)
CVE-2019-2923 mysql: Server: Security: Encryption unspecified vulnerability (CPU Oct 2019)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data.
External References:
http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Discussion:
Created mysql:5.7/community-mysql tracking bugs for this issue:
Affects: fedora-all [bug 1768177]
---
Created mysql:5.6/community-mysql tracking bugs
http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://security.netapp.com/advisory/ntap-20191017-0002/https://usn.ubuntu.com/4195-1/http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://security.netapp.com/advisory/ntap-20191017-0002/https://usn.ubuntu.com/4195-1/
2019-10-16
Published