Input validation error in MySQL Server - CVE-2013-5807
Published: October 16, 2013 / Updated: August 4, 2020
Vulnerability identifier: #VU33864
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-5807
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote #AU# to read and manipulate data.
Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.
Affected software
MySQL Server
mysql (Alpine package)
mysql (Alpine package)
How to mitigate CVE-2013-5807
Install update from vendor's website.
MySQL Server - update to 5.5.32
mysql (Alpine package) - update to 5.5.35-r0
mysql (Alpine package) - update to 5.5.35-r0
External References
- http://rhn.redhat.com/errata/RHSA-2014-0173.html
- http://rhn.redhat.com/errata/RHSA-2014-0186.html
- http://rhn.redhat.com/errata/RHSA-2014-0189.html
- http://security.gentoo.org/glsa/glsa-201409-04.xml
- http://www.debian.org/security/2013/dsa-2818
- http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
- http://www.securityfocus.com/bid/63105
- http://www.securitytracker.com/id/1029184
- http://www.ubuntu.com/usn/USN-2006-1