7.8
CVSSv2

CVE-2018-2585

Published: 18/01/2018 Updated: 23/01/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and prior and 6.10.4 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql connector\\/net

Vendor Advisories

Debian Bug report logs - #887751 mysql-connector-net: CVE-2018-2585 DoS via unauthenticated connection Package: mysql-connector-net; Maintainer for mysql-connector-net is Debian CLI Libraries Team <pkg-cli-libs-team@listsaliothdebianorg>; Reported by: Guido Günther <agx@sigxcpuorg> Date: Fri, 19 Jan 2018 16:39:05 ...