Improper Access Control - CVE-2018-2562

 

Improper Access Control - CVE-2018-2562

Published: January 22, 2018 / Updated: January 29, 2018


Vulnerability identifier: #VU10263
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-2562
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability exists due to an unspecified error in the MySQL Server. A remote authenticated attacker can exploit the vulnerability to modify certain data on the system and perform a denial of service (DoS) attack.


Affected software


Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse
Red Hat Software Collections
Percona Server for MySQL
mysql-5.5 (Debian package)
mariadb (Alpine package)
mariadb

How to mitigate CVE-2018-2562

Install updates from vednor's website.

mysql-5.5 (Debian package) - addressed in versions 5.5.59-0+deb7u1, 5.5.59-0+deb8u1
mariadb (Alpine package) - update to 10.1.32-r0
mariadb - addressed in versions 10.1.32-1.fc26, 10.2.13-1.fc27, 10.2.13-2.fc27, 10.2.13-2.fc28

External References

Related Security Bulletins