Vulnerability Name: | CVE-2013-0371 (CCN-81320) |
Assigned: | 2012-12-07 |
Published: | 2013-01-15 |
Updated: | 2022-08-26 |
Summary: | Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.
|
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): Required | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Low |
|
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Partial | 4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P) 3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Partial |
|
Vulnerability Type: | CWE-noinfo
|
Vulnerability Consequences: | Denial of Service |
References: | Source: MITRE Type: CNA CVE-2013-0371
Source: CCN Type: SA51894 Oracle MySQL Server Multiple Vulnerabilities
Source: SECUNIA Type: Not Applicable 53372
Source: GENTOO Type: Third Party Advisory GLSA-201308-06
Source: MANDRIVA Type: Broken Link MDVSA-2013:150
Source: CCN Type: Oracle Web site Oracle Critical Patch Update Advisory - January 2013
Source: CONFIRM Type: Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Source: CCN Type: BID-57415 Oracle MySQL Server CVE-2013-0371 Remote Security Vulnerability
Source: UBUNTU Type: Third Party Advisory USN-1703-1
Source: XF Type: UNKNOWN oracle-cpujan2013cve20130371-dos(81320)
Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:16451
Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-0371
|
Vulnerable Configuration: | Configuration 1: cpe:/a:oracle:mysql:*:*:*:*:*:*:*:* (Version >= 5.5.0 and <= 5.5.28) Configuration 2: cpe:/a:mariadb:mariadb:10.0.0:*:*:*:*:*:*:*OR cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 5.5.0 and < 5.5.29) Configuration 3: cpe:/o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*OR cpe:/o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*OR cpe:/o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*OR cpe:/o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* Configuration CCN 1: cpe:/a:oracle:mysql:5.5.0:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.1:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.2:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.3:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.4:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.5:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.8:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.1:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.10:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.11:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.12:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.13:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.14:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.15:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.16:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.17:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.18:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.19:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.20:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.21:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.9:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.7:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.6:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.23:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.22:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.26:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.24:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.25:a:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.25:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.27:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:5.5.28:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
Definition ID | Class | Title | Last Modified |
---|
oval:org.mitre.oval:def:16451 | V | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM). Supported versions that are affected are 5.5.28 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server | 2015-06-01 | oval:org.mitre.oval:def:18161 | P | USN-1703-1 -- mysql-5.1, mysql-5.5, mysql-dfsg-5.1 vulnerabilities | 2014-06-30 | oval:com.ubuntu.precise:def:20130371000 | V | CVE-2013-0371 on Ubuntu 12.04 LTS (precise) - medium. | 2013-01-16 |
|
BACK |