CVE-2017-10277
Published: 19 October 2017
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
Notes
Author | Note |
---|---|
mdeslaur | this isn't MySQL the database |
Priority
Status
Package | Release | Status |
---|---|---|
mariadb-10.0 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
zesty |
Does not exist
|
|
mariadb-10.1 Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
zesty |
Not vulnerable
|
|
mariadb-5.5 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
zesty |
Does not exist
|
|
mysql-5.5 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Not vulnerable
|
|
upstream |
Not vulnerable
|
|
vivid |
Does not exist
|
|
xenial |
Does not exist
|
|
zesty |
Does not exist
|
|
mysql-5.6 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
zesty |
Does not exist
|
|
mysql-5.7 Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
zesty |
Not vulnerable
|
|
percona-server-5.6 Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
zesty |
Not vulnerable
|
|
percona-xtradb-cluster-5.5 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Not vulnerable
|
|
xenial |
Does not exist
|
|
zesty |
Does not exist
|
|
percona-xtradb-cluster-5.6 Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
|
trusty |
Does not exist
|
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
zesty |
Not vulnerable
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.4 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | Low |
Integrity impact | Low |
Availability impact | None |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |