Improper Access Control - CVE-2018-2612

 

Improper Access Control - CVE-2018-2612

Published: January 22, 2018 / Updated: January 29, 2018


Vulnerability identifier: #VU10265
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-2612
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability exists due to an unspecified error in the MySQL Server. A remote privileged user can exploit the vulnerability to modify or delete certain data in database.


Affected software


Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
Ubuntu
Fedora
Opensuse
Red Hat Software Collections
mariadb (Alpine package)
community-mysql
rh-mysql57-mysql (Red Hat package)
mariadb

How to mitigate CVE-2018-2612

Install updates from vednor's website.

mariadb (Alpine package) - update to 10.1.32-r0
community-mysql - addressed in versions 5.7.21-1.fc27, 5.7.21-6.fc26
rh-mysql57-mysql (Red Hat package) - addressed in versions 5.7.21-2.el6.1, 5.7.21-2.el7.1
mariadb - addressed in versions 10.1.32-1.fc26, 10.2.13-1.fc27, 10.2.13-2.fc27, 10.2.13-2.fc28

External References

Related Security Bulletins