VulnerabilityModified
CVE-2015-4870
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
MEDIUM 4.0EPSS 30.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 30.15% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- oracle/linux · oracle/solaris · opensuse/leap · opensuse/opensuse · oracle/mysql · mariadb/mariadb · canonical/ubuntu linux · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · fedoraproject/fedora
- Source
- secalert_us@oracle.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177539.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00011.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00039.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/137232/MySQL-Procedure-Analyse-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0534.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0705.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1480.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1481.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3377Third Party Advisory
- http://www.debian.org/security/2015/dsa-3385Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlVendor Advisory
- http://www.securityfocus.com/bid/77208Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1033894Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2781-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1132Third Party Advisory
- https://www.exploit-db.com/exploits/39867/Exploit, Third Party Advisory, VDB Entry
- https://www.suse.com/support/update/announcement/2016/suse-su-20160296-1.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177539.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00011.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00039.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/137232/MySQL-Procedure-Analyse-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0534.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0705.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1480.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1481.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3377Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.