SB2013051601 - Input validation error in mysql (Alpine package)
Published: May 16, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2013-1502)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local #AU# to perform service disruption.
Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.9 and earlier allows local users to affect availability via unknown vectors related to Server Partition.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=cd012b8a5260e3c1b667747299719928d4951591
- https://git.alpinelinux.org/aports/commit/?id=38fb81b4612379a5a63b65e061044862d04da0f1
- https://git.alpinelinux.org/aports/commit/?id=e8b58a076c5cc1384ae30aa4751f463220c0dee3
- https://git.alpinelinux.org/aports/commit/?id=b96110fab261175d6e1957999a61187e527eef7d