Executive Summary
Summary | |
---|---|
Title | MySQL vulnerabilities |
Informations | |||
---|---|---|---|
Name | USN-2006-1 | First vendor Publication | 2013-10-24 |
Vendor | Ubuntu | Last vendor Modification | 2013-10-24 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:S/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.9 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Medium |
Cvss Expoit Score | 6.8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.10 - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-5.5: MySQL database - mysql-dfsg-5.1: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.1.72 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS, Ubuntu 12.10, Ubuntu 13.04 and Ubuntu 13.10 have been updated to MySQL 5.5.34. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-72.html http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-34.html http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: Ubuntu 13.04: Ubuntu 12.10: Ubuntu 12.04 LTS: Ubuntu 10.04 LTS: In general, a standard system update will make all the necessary changes. References: Package Information: |
Original Source
Url : http://www.ubuntu.com/usn/USN-2006-1 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:19387 | |||
Oval ID: | oval:org.mitre.oval:def:19387 | ||
Title: | USN-2006-1 -- mysql-5.5, mysql-dfsg-5.1 vulnerabilities | ||
Description: | Several security issues were fixed in MySQL. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2006-1 CVE-2013-3839 CVE-2013-5807 | Version: | 5 |
Platform(s): | Ubuntu 13.10 Ubuntu 13.04 Ubuntu 12.10 Ubuntu 12.04 Ubuntu 10.04 | Product(s): | mysql-5.5 mysql-dfsg-5.1 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:19679 | |||
Oval ID: | oval:org.mitre.oval:def:19679 | ||
Title: | DSA-2780-1 mysql-5.1 - several | ||
Description: | This DSA updates the MySQL database to 5.1.72. This fixes multiple unspecified security problems in the Optimizer component: <a href="http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html">http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</a> | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2780-1 CVE-2012-2750 CVE-2013-3839 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | mysql-5.1 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:20803 | |||
Oval ID: | oval:org.mitre.oval:def:20803 | ||
Title: | DSA-2818-1 mysql-5.5 - several | ||
Description: | Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to a new upstream version, 5.5.33, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly incompatible changes. Please see the MySQL 5.5 Release Notes for further details. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2818-1 CVE-2013-1861 CVE-2013-2162 CVE-2013-3783 CVE-2013-3793 CVE-2013-3802 CVE-2013-3804 CVE-2013-3809 CVE-2013-3812 CVE-2013-3839 CVE-2013-5807 | Version: | 5 |
Platform(s): | Debian GNU/Linux 7 Debian GNU/kFreeBSD 7 | Product(s): | mysql-5.5 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2013-10-17 | IAVM : 2013-A-0201 - Multiple Vulnerabilities in Oracle MySQL Products Severity : Category I - VMSKEY : V0040782 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-12-22 | Name : The remote device is affected by multiple vulnerabilities. File : juniper_space_jsa10627.nasl - Type : ACT_GATHER_INFO |
2014-09-05 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201409-04.nasl - Type : ACT_GATHER_INFO |
2014-03-07 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-0189.nasl - Type : ACT_GATHER_INFO |
2014-03-07 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-0173.nasl - Type : ACT_GATHER_INFO |
2014-02-20 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-0186.nasl - Type : ACT_GATHER_INFO |
2014-02-19 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-0186.nasl - Type : ACT_GATHER_INFO |
2014-02-19 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-0186.nasl - Type : ACT_GATHER_INFO |
2014-02-19 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20140218_mysql55_mysql_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2013-12-17 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2818.nasl - Type : ACT_GATHER_INFO |
2013-11-14 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2013-240.nasl - Type : ACT_GATHER_INFO |
2013-11-11 | Name : The remote Fedora host is missing a security update. File : fedora_2013-19601.nasl - Type : ACT_GATHER_INFO |
2013-11-02 | Name : The remote Fedora host is missing a security update. File : fedora_2013-19648.nasl - Type : ACT_GATHER_INFO |
2013-11-02 | Name : The remote Fedora host is missing a security update. File : fedora_2013-19654.nasl - Type : ACT_GATHER_INFO |
2013-10-25 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2006-1.nasl - Type : ACT_GATHER_INFO |
2013-10-20 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2780.nasl - Type : ACT_GATHER_INFO |
2013-10-16 | Name : The remote database server may be affected by multiple vulnerabilities. File : mysql_5_6_13.nasl - Type : ACT_GATHER_INFO |
2013-10-16 | Name : The remote database server may be affected by multiple vulnerabilities. File : mysql_5_5_33.nasl - Type : ACT_GATHER_INFO |
2013-10-16 | Name : The remote database server may be affected by a denial of service vulnerability. File : mysql_5_1_71.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 12:02:41 |
|
2013-10-24 21:21:45 |
|