Information disclosure - CVE-2017-3313

 

Information disclosure - CVE-2017-3313

Published: June 2, 2017 / Updated: June 5, 2017


Vulnerability identifier: #VU6896
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3313
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local high privileged attacker to obtain potentially sensitive information.

The weakness exists due to an error in MyISAM component. A local attacker can gain unauthorized access to critical data or complete access to all MySQL Server accessible data.

Successful exploitation of the vulnerability results in information disclosure.

Affected software


Amazon Linux AMI
SUSE Linux
Slackware Linux
Opensuse
mariadb (Alpine package)

How to mitigate CVE-2017-3313

Install update from vendor's website.

mariadb (Alpine package) - update to 10.1.22-r0

External References

Related Security Bulletins