Security restrictions bypass - CVE-2018-2786
Published: April 20, 2018
Vulnerability identifier: #VU12028
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-2786
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to write arbitrary files and cause DoS condition on the target system.
The weakness exists in the MySQL Server component of Oracle MySQL due to improper security restrictions. A remote attacker can update, insert or delete some of MySQL Server accessible data and cause the service to crash.
The weakness exists in the MySQL Server component of Oracle MySQL due to improper security restrictions. A remote attacker can update, insert or delete some of MySQL Server accessible data and cause the service to crash.
Affected software
Amazon Linux AMI
Fedora
Tivoli Network Manager IP Edition
mariadb (Alpine package)
openSUSE Leap
community-mysql
mariadb
How to mitigate CVE-2018-2786
Install update from vendor's website.
mariadb (Alpine package) - update to 10.2.15-r0
community-mysql - addressed in versions 5.7.22-1.fc26, 5.7.22-1.fc27, 5.7.22-1.fc28
mariadb - addressed in versions 10.2.15-2.fc27, 10.2.15-2.fc28
community-mysql - addressed in versions 5.7.22-1.fc26, 5.7.22-1.fc27, 5.7.22-1.fc28
mariadb - addressed in versions 10.2.15-2.fc27, 10.2.15-2.fc28
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle MySQL
- Amazon Linux AMI update for mysql57
- OpenSUSE Linux update for mariadb
- Security restrictions bypass in mariadb (Alpine package)
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition
- Fedora 28 update for community-mysql
- Fedora 27 update for community-mysql
- Fedora 26 update for community-mysql
- Fedora 28 update for mariadb
- Fedora 27 update for mariadb