CVE-2016-3492: Medium severity mysql vulnerability
Published Oct 25, 2016
·Updated
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer.
Affected Software
21 affected components
Oracle MySQL>=5.5.0<=5.5.51
Oracle MySQL>=5.6.0<=5.6.32
Oracle MySQL>=5.7.0<=5.7.14
MariaDB MariaDB>=5.5.0<5.5.52
MariaDB MariaDB>=10.0.0<10.0.28
MariaDB MariaDB>=10.1.0<10.1.18
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Eus=7.3
redhat Enterprise Linux Eus=7.4
redhat Enterprise Linux Eus=7.5
redhat Enterprise Linux Eus=7.6
redhat Enterprise Linux Eus=7.7
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Server Tus=7.7
redhat Enterprise Linux Workstation=7.0
Remediation
Event History
Oct 25, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3492?
CVE-2016-3492 is categorized as a vulnerability that can affect availability.
2
How do I fix CVE-2016-3492?
To fix CVE-2016-3492, upgrade Oracle MySQL to versions later than 5.5.51, 5.6.32, or 5.7.14.
3
Which versions of MySQL are affected by CVE-2016-3492?
CVE-2016-3492 affects Oracle MySQL versions 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier.
4
Are MariaDB versions vulnerable to CVE-2016-3492?
Yes, certain MariaDB versions are vulnerable as they fall within the affected version ranges for CVE-2016-3492.
5
Can remote authenticated users exploit CVE-2016-3492?
Yes, remote authenticated users can exploit CVE-2016-3492 to impact the availability of the server.