First published: Wed Oct 16 2019(Updated: )
Last updated 24 July 2024
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mysql | <5.6.46 | 5.6.46 |
redhat/mysql | <5.7.28 | 5.7.28 |
redhat/mysql | <8.0.18 | 8.0.18 |
redhat/mariadb | <5.5.66 | 5.5.66 |
redhat/mariadb | <10.4.9 | 10.4.9 |
redhat/mariadb | <10.3.19 | 10.3.19 |
redhat/mariadb | <10.2.28 | 10.2.28 |
redhat/mariadb | <10.1.42 | 10.1.42 |
debian/mariadb-10.1 | ||
debian/mysql-5.7 | ||
Oracle MySQL | >=5.6.0<=5.6.45 | |
Oracle MySQL | >=5.7.0<=5.7.27 | |
Oracle MySQL | >=8.0.0<=8.0.17 | |
MariaDB | >=5.5.0<5.5.66 | |
MariaDB | >=10.1.0<10.1.42 | |
MariaDB | >=10.2.0<10.2.28 | |
MariaDB | >=10.3.0<10.3.19 | |
MariaDB | >=10.4.0<10.4.9 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Ubuntu | =19.10 | |
Fedora | =29 | |
Fedora | =30 | |
Fedora | =31 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2974 is classified as an easily exploitable vulnerability that can be exploited by low privileged attackers with network access.
To fix CVE-2019-2974, update MySQL to version 5.6.46 or later, version 5.7.28 or later, or version 8.0.18 or later.
Affected versions of MySQL include 5.6.45 and prior, 5.7.27 and prior, and 8.0.17 and prior.
Yes, MariaDB versions up to 5.5.66, 10.1.42, 10.2.28, 10.3.19, and 10.4.9 are also affected by CVE-2019-2974.
An attacker can exploit CVE-2019-2974 through network access by leveraging vulnerabilities in the MySQL Server: Optimizer component.