CVE-2018-2583: Medium severity mysql vulnerability
Last updated 24 July 2024
Other sources
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Stored Procedure). Supported versions that are affected are 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
— Red Hat
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Stored Procedure). Supported versions that are affected are 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2583?
CVE-2018-2583 has been classified as a high severity vulnerability due to the ease with which it can be exploited by privileged attackers.
How do I fix CVE-2018-2583?
To remediate CVE-2018-2583, upgrade your MySQL Server to version 5.6.39 or 5.7.21 or higher.
Which MySQL versions are affected by CVE-2018-2583?
CVE-2018-2583 affects MySQL versions 5.6.38 and earlier, as well as 5.7.20 and earlier.
Can CVE-2018-2583 be exploited remotely?
Yes, CVE-2018-2583 can be easily exploited by attackers with network access, making it a critical security concern.
What components of MySQL does CVE-2018-2583 impact?
CVE-2018-2583 specifically impacts the MySQL Server component, particularly the Stored Procedure subcomponent.