CVE-2018-2600

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
oraclemysql
5.7.0 ≤
𝑥
≤ 5.7.20
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mariadb-10.0
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
not-affected
mariadb-10.1
artful
ignored
bionic
not-affected
cosmic
not-affected
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
dne
mariadb-5.5
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
dne
mysql-5.5
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
not-affected
vivid
dne
xenial
dne
mysql-5.6
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
dne
mysql-5.7
artful
Fixed 5.7.21-0ubuntu0.17.10.1
released
bionic
Fixed 5.7.21-1ubuntu1
released
cosmic
Fixed 5.7.21-1ubuntu1
released
disco
Fixed 5.7.21-1ubuntu1
released
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
Fixed 5.7.21-0ubuntu0.16.04.1
released
mysql-8.0
bionic
dne
disco
dne
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
trusty
dne
xenial
dne
percona-server-5.6
artful
ignored
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
not-affected
percona-xtradb-cluster-5.5
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
dne
percona-xtradb-cluster-5.6
artful
ignored
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
trusty
dne
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
mysql-config
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql55
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql55-bench
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql55-debuginfo
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql55-devel
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql55-embedded
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql55-embedded-devel
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql55-libs
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql55-server
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql55-test
Amazon Linux 1
0:5.5.59-1.20.amzn1
fixed
mysql56
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-bench
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-common
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-debuginfo
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-devel
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-embedded
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-embedded-devel
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-errmsg
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-libs
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-server
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql56-test
Amazon Linux 1
0:5.6.39-1.28.amzn1
fixed
mysql57
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed
mysql57-common
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed
mysql57-debuginfo
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed
mysql57-devel
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed
mysql57-embedded
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed
mysql57-embedded-devel
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed
mysql57-errmsg
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed
mysql57-libs
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed
mysql57-server
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed
mysql57-test
Amazon Linux 1
0:5.7.21-2.6.amzn1
fixed