Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows local users to affect confidentiality and integrity via unknown vectors related to Server Install.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2013-2391 from the MITRE CVE dictionary dictionary and NIST NVD.
On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Base Score | 3 |
---|---|
Base Metrics | AV:L/AC:M/Au:S/C:P/I:P/A:N |
Access Vector | Local |
Access Complexity | Medium |
Authentication | Single |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux 6 (mysql) | RHSA-2013:0772 | 2013-04-25 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux 5 | mysql | Will not fix |