CVE-2019-2617: Medium severity mysql vulnerability
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Other sources
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2617?
CVE-2019-2617 is considered a difficult-to-exploit vulnerability that affects high privileged users with network access.
How do I fix CVE-2019-2617?
To fix CVE-2019-2617, upgrade to MySQL Server version 8.0.16 or later.
Which MySQL versions are affected by CVE-2019-2617?
MySQL Server versions 8.0.15 and prior are affected by CVE-2019-2617.
What components does CVE-2019-2617 impact?
CVE-2019-2617 impacts the MySQL Server component, specifically the Server: Replication subcomponent.
Who can exploit CVE-2019-2617?
CVE-2019-2617 can be exploited by high privileged attackers with network access through multiple protocols.