First published: Wed Jan 17 2018(Updated: )
Last updated 24 July 2024
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mysql | <5.5.59 | 5.5.59 |
redhat/mysql | <5.6.39 | 5.6.39 |
redhat/mysql | <5.7.21 | 5.7.21 |
redhat/mariadb | <5.5.59 | 5.5.59 |
redhat/mariadb | <10.2.13 | 10.2.13 |
redhat/mariadb | <10.1.31 | 10.1.31 |
redhat/mariadb | <10.0.34 | 10.0.34 |
debian/mariadb-10.0 | ||
debian/mysql-5.5 | ||
debian/mysql-5.7 | ||
MySQL | >=5.5.0<=5.5.58 | |
MySQL | >=5.6.0<=5.6.38 | |
MySQL | >=5.7.0<=5.7.20 | |
MariaDB | >=5.5.0<5.5.59 | |
MariaDB | >=10.0.0<10.0.34 | |
MariaDB | >=10.1.0<10.1.31 | |
MariaDB | >=10.2.0<10.2.13 | |
Debian Linux | =7.0 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =17.10 | |
NetApp Active IQ Unified Manager | >=7.3 | |
NetApp Active IQ Unified Manager for VMware vSphere | >=9.5 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp SnapCenter | ||
Red Hat OpenStack for IBM Power | =12 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server EUS | =7.5 | |
Red Hat Enterprise Linux Server EUS | =7.6 | |
Red Hat Enterprise Linux Server EUS | =7.7 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2665 is classified as an easily exploitable vulnerability that affects multiple versions of MySQL and MariaDB.
To fix CVE-2018-2665, upgrade to MySQL version 5.5.59, 5.6.39, or 5.7.21, or the corresponding secure versions of MariaDB.
CVE-2018-2665 affects MySQL versions 5.5.58 and prior, 5.6.38 and prior, and 5.7.20 and prior.
Yes, MariaDB versions 5.5.58 and prior, 10.0.33 and prior, 10.1.30 and prior, and 10.2.12 and prior are affected by CVE-2018-2665.
Exploiting CVE-2018-2665 may allow a low-privileged attacker with network access to compromise vulnerable systems.