MySQL 5.6.x < 5.6.40 Multiple Vulnerabilities (April 2018 CPU)

medium Nessus 插件 ID 109168
全新!漏洞优先级评级 (VPR)

Tenable 测算每个漏洞的动态 VPR。VPR 将漏洞信息与威胁情报和机器学习算法相结合,预测哪些漏洞最有可能在攻击中被利用。了解详细信息: VPR 的定义及其与 CVSS 的区别。

VPR 得分: 7.3

简介

The remote database server is affected by multiple vulnerabilities.

描述

The version of MySQL running on the remote host is 5.6.x prior to 5.6.40. It is, therefore, affected by multiple vulnerabilities as noted in the April 2018 Critical Patch Update advisory. Please consult the CVRF details for the applicable CVEs for additional information.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

解决方案

Upgrade to MySQL version 5.6.40 or later.

另见

http://www.nessus.org/u?76507bf8

http://www.nessus.org/u?64303a9a

https://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-40.html

插件详情

严重性: Medium

ID: 109168

文件名: mysql_5_6_40.nasl

版本: 1.6

类型: remote

系列: Databases

发布时间: 2018/4/19

最近更新时间: 2019/11/8

依存关系: mysql_version.nasl, mysql_login.nasl

配置: 启用偏执模式

风险信息

风险因素: Medium

VPR 得分: 7.3

CVSS 得分来源: CVE-2018-2787

CVSS v2.0

基本分数: 5.5

时间分数: 4.1

矢量: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P

时间矢量: CVSS2#E:U/RL:OF/RC:C

CVSS v3.0

基本分数: 5.5

时间分数: 4.8

矢量: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

漏洞信息

CPE: cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*

必需的 KB 项: Settings/ParanoidReport

易利用性: No known exploits are available

补丁发布日期: 2018/4/17

漏洞发布日期: 2018/4/17

参考资料信息

CVE: CVE-2018-2755, CVE-2018-2761, CVE-2018-2771, CVE-2018-2773, CVE-2018-2781, CVE-2018-2813, CVE-2018-2817, CVE-2018-2818, CVE-2018-2819, CVE-2018-2766, CVE-2018-2782, CVE-2018-2784, CVE-2018-2787, CVE-2018-2758, CVE-2018-2805

BID: 103802, 103828, 103778, 103804, 103830, 103824, 103814