SB2017051905 - Amazon Linux AMI update for mysql55
Published: May 19, 2017 Updated: May 24, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 secuirty vulnerabilities.
1) Security restrictions bypass (CVE-ID: CVE-2017-3462)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.The weakness exists in MySQL Server due to improper security restrictions. A remote attacker can cause the service to crash.
2) Security restrictions bypass (CVE-ID: CVE-2017-3463)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.The weakness exists in MySQL Server due to improper security restrictions. A remote attacker can cause the service to crash.
3) Security restrictions bypass (CVE-ID: CVE-2017-3461)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.The weakness exists in MySQL Server due to improper security restrictions. A remote attacker can cause the service to crash.
4) Security restrictions bypass (CVE-ID: CVE-2017-3464)
The vulnerability allows a remote authenticated attacker to write arbitrary files on the target system.The weakness exists in MySQL Server due to improper security restrictions. A remote attacker can update, insert or delete some of MySQL Server accessible data.
5) CVE-2017-3265 (CVE-ID: CVE-2017-3265)
6) Security restrictions bypass (CVE-ID: CVE-2017-3309)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.The weakness exists in MySQL Server due to improper security restrictions. A remote attacker can cause the service to crash.
7) Security restrictions bypass (CVE-ID: CVE-2017-3308)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.The weakness exists in MySQL Server due to improper security restrictions. A remote attacker can cause the service to crash.
8) Security restrictions bypass (CVE-ID: CVE-2017-3456)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.The weakness exists in MySQL Server due to improper security restrictions. A remote attacker can cause the service to crash.
9) Security restrictions bypass (CVE-ID: CVE-2017-3453)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.The weakness exists in MySQL Server due to improper security restrictions. A remote attacker can cause the service to crash.
10) Security restrictions bypass (CVE-ID: CVE-2017-3450)
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.The weakness exists in MySQL Server due to improper security restrictions. A remote attacker can cause the service to crash.
Remediation
Install update from vendor's website.