SB2019032610 - Amazon Linux AMI update for mysql56
Published: March 26, 2019 Updated: May 22, 2019
Security Bulletin ID
SB2019032610
Severity
Low
Patch available
YES
Number of vulnerabilities
9
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 secuirty vulnerabilities.
1) Denial of service (CVE-ID: CVE-2019-2507)
The vulnerability allows a remote authenticated high-privileged attacker to cause DoS condition.The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can cause the service to crash.
2) Denial of service (CVE-ID: CVE-2019-2481)
The vulnerability allows a remote authenticated high-privileged attacker to cause DoS condition.The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can cause the service to crash.
3) Denial of service (CVE-ID: CVE-2019-2482)
The vulnerability allows a remote authenticated attacker to cause DoS condition.The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can cause the service to crash.
4) Security restrictions bypass (CVE-ID: CVE-2019-2503)
The vulnerability allows an adjacent authenticated attacker to bypass security restrictions.The weakness exists in MySQL Protocol due to unspecified flaw. An adjacent attacker can bypass security restrictions to read potentially sensitive information and cause the service to crash.
5) Security restrictions bypass (CVE-ID: CVE-2019-2534)
The vulnerability allows a remote authenticated attacker to bypass security restrictions.The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can bypass security restrictions to read potentially sensitive information and modify arbitrary data.
6) Denial of service (CVE-ID: CVE-2019-2537)
The vulnerability allows a remote authenticated high-privileged attacker to cause DoS condition.The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can cause the service to crash.
7) Denial of service (CVE-ID: CVE-2019-2531)
The vulnerability allows a remote authenticated high-privileged attacker to cause DoS condition.The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can cause the service to crash.
8) Denial of service (CVE-ID: CVE-2019-2455)
The vulnerability allows a remote authenticated attacker to cause DoS condition.The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can cause the service to crash.
9) Denial of service (CVE-ID: CVE-2019-2529)
The vulnerability allows a remote authenticated attacker to cause DoS condition.The weakness exists in MySQL Protocol due to unspecified flaw. A remote attacker can cause the service to crash.
Remediation
Install update from vendor's website.