First published: Wed Jan 16 2019(Updated: )
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handling). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.4 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H).
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mariadb-10.0 | ||
debian/mysql-5.7 | ||
redhat/mysql | <5.6.43 | 5.6.43 |
redhat/mysql | <5.7.25 | 5.7.25 |
redhat/mysql | <8.0.14 | 8.0.14 |
redhat/mariadb | <5.5.62 | 5.5.62 |
redhat/mariadb | <10.3.10 | 10.3.10 |
redhat/mariadb | <10.2.18 | 10.2.18 |
redhat/mariadb | <10.1.36 | 10.1.36 |
redhat/mariadb | <10.0.37 | 10.0.37 |
ubuntu/mariadb-10.0 | <10.0.38-0ubuntu0.16.04.1 | 10.0.38-0ubuntu0.16.04.1 |
ubuntu/mariadb-10.1 | <1:10.1.38-0ubuntu0.18.04.1 | 1:10.1.38-0ubuntu0.18.04.1 |
ubuntu/mariadb-10.1 | <1:10.1.38-0ubuntu0.18.10.2 | 1:10.1.38-0ubuntu0.18.10.2 |
ubuntu/mariadb-10.1 | <10.1.36 | 10.1.36 |
ubuntu/mariadb-5.5 | <5.5.63-1ubuntu0.14.04.1 | 5.5.63-1ubuntu0.14.04.1 |
ubuntu/mysql-5.6 | <5.6.43 | 5.6.43 |
ubuntu/mysql-5.7 | <5.7.25-0ubuntu0.18.04.2 | 5.7.25-0ubuntu0.18.04.2 |
ubuntu/mysql-5.7 | <5.7.25-0ubuntu0.18.10.2 | 5.7.25-0ubuntu0.18.10.2 |
ubuntu/mysql-5.7 | <5.7.25-1 | 5.7.25-1 |
ubuntu/mysql-5.7 | <5.7.25 | 5.7.25 |
ubuntu/mysql-5.7 | <5.7.25-0ubuntu0.16.04.2 | 5.7.25-0ubuntu0.16.04.2 |
Oracle MySQL | >=5.6.0<=5.6.42 | |
Oracle MySQL | >=5.7.0<=5.7.24 | |
Oracle MySQL | >=8.0.0<=8.0.13 | |
Mariadb Mariadb | >=5.5.0<5.5.62 | |
Mariadb Mariadb | >=10.0.0<10.0.37 | |
Mariadb Mariadb | >=10.1.0<10.1.36 | |
Mariadb Mariadb | >=10.2.0<10.2.18 | |
Mariadb Mariadb | >=10.3.0<10.3.10 | |
Netapp Active Iq Unified Manager Windows | >=7.3 | |
Netapp Active Iq Unified Manager Vmware Vsphere | >=9.5 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Netapp Snapcenter | ||
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Desktop | =8.0 | |
Redhat Enterprise Linux Eus | =8.1 | |
Redhat Enterprise Linux Eus | =8.2 | |
Redhat Enterprise Linux Eus | =8.4 | |
Redhat Enterprise Linux Eus | =8.6 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server | =8.0 | |
Redhat Enterprise Linux Server Aus | =8.2 | |
Redhat Enterprise Linux Server Aus | =8.4 | |
Redhat Enterprise Linux Server Aus | =8.6 | |
Redhat Enterprise Linux Server Tus | =8.2 | |
Redhat Enterprise Linux Server Tus | =8.4 | |
Redhat Enterprise Linux Server Tus | =8.6 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Redhat Enterprise Linux Workstation | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2503 is a vulnerability in the MySQL Server component of Oracle MySQL that allows a low privileged attacker to exploit the server's connection handling mechanism.
The affected software versions are 5.6.42 and prior, 5.7.24 and prior, and 8.0.13 and prior.
The severity level of CVE-2019-2503 is medium, with a CVSS score of 6.4.
To fix CVE-2019-2503 vulnerability in MySQL, update to version 5.6.43 (for 5.6.x), 5.7.25 (for 5.7.x), or 8.0.14 (for 8.0.x) or later.
You can find more information about CVE-2019-2503 vulnerability in the official Oracle security advisory and the Red Hat Bugzilla reports.