Denial of service in MySQL Server - CVE-2019-2529
Published: January 17, 2019
Vulnerability identifier: #VU17025
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2529
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition.
The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can cause the service to crash.
The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can cause the service to crash.
Affected software
MySQL Server
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
Fedora
Opensuse
Tivoli Network Manager IP Edition
Data Computing Appliance (DCA)
mysql-5.7 (Ubuntu package)
mariadb (Alpine package)
mariadb (Red Hat package)
community-mysql
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
Fedora
Opensuse
Tivoli Network Manager IP Edition
Data Computing Appliance (DCA)
mysql-5.7 (Ubuntu package)
mariadb (Alpine package)
mariadb (Red Hat package)
community-mysql
How to mitigate CVE-2019-2529
Install update from vendor's website.
MySQL Server - addressed in versions 5.6.43, 5.7.25, 8.0.14
mysql-5.7 (Ubuntu package) - addressed in versions 5.7.25-0ubuntu0.16.04.2, 5.7.25-0ubuntu0.18.04.2, 5.7.25-0ubuntu0.18.10.2
mariadb (Alpine package) - update to 10.1.38-r0
Data Computing Appliance (DCA) - update to 4.3.0.0
mariadb (Red Hat package) - update to 5.5.64-1.el7
community-mysql - addressed in versions 5.7.25-1.fc28, 8.0.15-1.fc29
mysql-5.7 (Ubuntu package) - addressed in versions 5.7.25-0ubuntu0.16.04.2, 5.7.25-0ubuntu0.18.04.2, 5.7.25-0ubuntu0.18.10.2
mariadb (Alpine package) - update to 10.1.38-r0
Data Computing Appliance (DCA) - update to 4.3.0.0
mariadb (Red Hat package) - update to 5.5.64-1.el7
community-mysql - addressed in versions 5.7.25-1.fc28, 8.0.15-1.fc29
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle MySQL
- Ubuntu update for MySQL
- Slackware Linux update for mariadb
- OpenSUSE Linux update for mysql-community-server
- Amazon Linux AMI update for mysql56
- Amazon Linux AMI update for mysql57
- Denial of service in mariadb (Alpine package)
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 7 update for mariadb
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition
- Fedora 29 update for community-mysql
- Fedora 28 update for community-mysql
- Multiple vulnerabilities in MySQL Server