CVE-2019-2628
Published on: 04/23/2019 12:00:00 AM UTC
Last Modified on: 08/05/2022 02:27:00 PM UTC
Certain versions of Ubuntu Linux from Canonical contain the following vulnerability:
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
- CVE-2019-2628 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Oracle Corporation - MySQL Server version = 5.7.25 and prior
- Affected Vendor/Software:
Oracle Corporation - MySQL Server version = 8.0.15 and prior
CVSS3 Score: 4.9 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Oracle Critical Patch Update - April 2019 | Patch Vendor Advisory web.archive.org text/html Inactive LinkNot Archived |
![]() |
No Description Provided | Third Party Advisory support.f5.com text/html |
![]() |
[security-announce] openSUSE-SU-2019:1915-1: important: Security update | lists.opensuse.org text/html |
![]() |
[security-announce] openSUSE-SU-2019:1913-1: important: Security update | lists.opensuse.org text/html |
![]() |
USN-4070-3: MariaDB vulnerabilities | Ubuntu security notices | Ubuntu | usn.ubuntu.com text/html |
![]() |
Red Hat Customer Portal | access.redhat.com text/html |
![]() |
Red Hat Customer Portal | access.redhat.com text/html |
![]() |
Red Hat Customer Portal | access.redhat.com text/html |
![]() |
USN-3957-1: MySQL vulnerabilities | Ubuntu security notices | Ubuntu | Third Party Advisory usn.ubuntu.com text/html |
![]() |
Related QID Numbers
- 159650 Oracle Enterprise Linux Security Update for mariadb:10.3 security and bug fix update (ELSA-2019-3708)
- 296081 Oracle Solaris 11.4 Support Repository Update (SRU) 12.5.0 Missing (CPUJUL2019)
- 377107 Alibaba Cloud Linux Security Update for mysql:8.0 (ALINUX3-SA-2022:0107)
- 377122 Alibaba Cloud Linux Security Update for mariadb:10.3 and mariadb-devel:10.3 (ALINUX3-SA-2021:0030)
- 500379 Alpine Linux Security Update for mariadb
- 940079 AlmaLinux Security Update for mysql:8.0 (ALSA-2019:2511)
- 940341 AlmaLinux Security Update for mariadb:10.3 (ALSA-2019:3708)
- 960793 Rocky Linux Security Update for mysql:8.0 (RLSA-2019:2511)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 18.10 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 18.10 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
Application | Mariadb | Mariadb | All | All | All | All |
Operating System | Opensuse | Leap | 15.0 | All | All | All |
Operating System | Opensuse | Leap | 15.1 | All | All | All |
Application | Oracle | Mysql | All | All | All | All |
Application | Oracle | Mysql | All | All | All | All |
Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
Operating System | Redhat | Enterprise Linux Eus | 8.1 | All | All | All |
Operating System | Redhat | Enterprise Linux Eus | 8.2 | All | All | All |
Operating System | Redhat | Enterprise Linux Eus | 8.4 | All | All | All |
Operating System | Redhat | Enterprise Linux Eus | 8.6 | All | All | All |
Operating System | Redhat | Enterprise Linux Server Aus | 8.2 | All | All | All |
Operating System | Redhat | Enterprise Linux Server Aus | 8.4 | All | All | All |
Operating System | Redhat | Enterprise Linux Server Aus | 8.6 | All | All | All |
Operating System | Redhat | Enterprise Linux Server Tus | 8.2 | All | All | All |
Operating System | Redhat | Enterprise Linux Server Tus | 8.4 | All | All | All |
Operating System | Redhat | Enterprise Linux Server Tus | 8.6 | All | All | All |
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*:
- cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*:
- cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*:
- cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE