4 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:S/C:P/I:N/A:N
6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
0.003 Low
EPSS
Percentile
65.6%
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent:
Client programs). Supported versions that are affected are 5.5.57 and
earlier, 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable
vulnerability allows low privileged attacker with network access via
multiple protocols to compromise MySQL Server. Successful attacks of this
vulnerability can result in unauthorized access to critical data or
complete access to all MySQL Server accessible data. CVSS 3.0 Base Score
6.5 (Confidentiality impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 14.04 | noarch | mysql-5.5 | < 5.5.58-0ubuntu0.14.04.1 | UNKNOWN |
ubuntu | 17.10 | noarch | mysql-5.7 | < 5.7.20-0ubuntu0.17.10.1 | UNKNOWN |
ubuntu | 18.04 | noarch | mysql-5.7 | < 5.7.20-0ubuntu0.17.10.1 | UNKNOWN |
ubuntu | 18.10 | noarch | mysql-5.7 | < 5.7.20-0ubuntu0.17.10.1 | UNKNOWN |
ubuntu | 19.04 | noarch | mysql-5.7 | < 5.7.20-0ubuntu0.17.10.1 | UNKNOWN |
ubuntu | 16.04 | noarch | mysql-5.7 | < 5.7.20-0ubuntu0.16.04.1 | UNKNOWN |
ubuntu | 17.04 | noarch | mysql-5.7 | < 5.7.20-0ubuntu0.17.04.1 | UNKNOWN |
ubuntu | 16.04 | noarch | percona-server-5.6 | < any | UNKNOWN |
ubuntu | 16.04 | noarch | percona-xtradb-cluster-5.6 | < any | UNKNOWN |
www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
launchpad.net/bugs/cve/CVE-2017-10379
nvd.nist.gov/vuln/detail/CVE-2017-10379
security-tracker.debian.org/tracker/CVE-2017-10379
ubuntu.com/security/notices/USN-3459-1
ubuntu.com/security/notices/USN-3459-2
www.cve.org/CVERecord?id=CVE-2017-10379
4 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:S/C:P/I:N/A:N
6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
0.003 Low
EPSS
Percentile
65.6%