Improper input validation - CVE-2018-2668
Published: January 22, 2018 / Updated: January 29, 2018
Vulnerability identifier: #VU10271
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-2668
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability exists due to an unspecified error in the MySQL Server. A remote authenticated attacker can exploit the vulnerability to perform a denial of service attack.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse
Red Hat Software Collections
Percona Server for MySQL
mysql-5.5 (Debian package)
mariadb (Alpine package)
community-mysql
rh-mysql57-mysql (Red Hat package)
mariadb
How to mitigate CVE-2018-2668
Install updates from vednor's website.
mysql-5.5 (Debian package) - addressed in versions 5.5.59-0+deb7u1, 5.5.59-0+deb8u1
mariadb (Alpine package) - update to 10.1.32-r0
community-mysql - addressed in versions 5.7.21-1.fc27, 5.7.21-6.fc26
rh-mysql57-mysql (Red Hat package) - addressed in versions 5.7.21-2.el6.1, 5.7.21-2.el7.1
mariadb - addressed in versions 10.1.32-1.fc26, 10.2.13-1.fc27, 10.2.13-2.fc27, 10.2.13-2.fc28
mariadb (Alpine package) - update to 10.1.32-r0
community-mysql - addressed in versions 5.7.21-1.fc27, 5.7.21-6.fc26
rh-mysql57-mysql (Red Hat package) - addressed in versions 5.7.21-2.el6.1, 5.7.21-2.el7.1
mariadb - addressed in versions 10.1.32-1.fc26, 10.2.13-1.fc27, 10.2.13-2.fc27, 10.2.13-2.fc28
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle MySQL Server
- Ubuntu update for MySQL
- Ubuntu update for MySQL
- Debian update for mysql-5.5
- Slackware Linux update for mariadb
- Multiple vulnerabilities in Percona Server for MySQL
- Amazon Linux AMI update for mysql55, mysql56, mysql57
- OpenSUSE Linux update for mysql-community-server
- SUSE Linux update for mariadb
- SUSE Linux update for mariadb
- OpenSUSE Linux update for mariadb
- Red Hat update for mysql
- Gentoo update for MySQL
- Red Hat update for mariadb
- Improper input validation in mariadb (Alpine package)
- Red Hat Software Collections update for rh-mysql57-mysql
- Fedora 27 update for community-mysql
- Fedora 26 update for community-mysql
- Fedora 27 update for mariadb
- Fedora 28 update for mariadb
- Fedora 27 update for mariadb
- Fedora 26 update for mariadb