MySQL 5.5 < 5.5.33 Multiple Vulnerabilities

medium Nessus Plugin ID 70462

Synopsis

The remote database server may be affected by multiple vulnerabilities.

Description

The version of MySQL 5.5 installed on the remote host is a version prior to 5.5.33. It is, therefore, potentially affected by vulnerabilities in the following components :

- Server Optimizer
- Server Replication

Solution

Upgrade to MySQL version 5.5.33 or later.

See Also

http://www.nessus.org/u?f2d5fae1

http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-33.html

Plugin Details

Severity: Medium

ID: 70462

File Name: mysql_5_5_33.nasl

Version: 1.6

Type: remote

Family: Databases

Published: 10/16/2013

Updated: 11/15/2018

Configuration: Enable paranoid mode

Supported Sensors: Frictionless Assessment Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Information

CPE: cpe:/a:oracle:mysql

Required KB Items: Settings/ParanoidReport

Exploit Ease: No known exploits are available

Patch Publication Date: 7/31/2013

Vulnerability Publication Date: 10/15/2013

Reference Information

CVE: CVE-2013-3839, CVE-2013-5807

BID: 63105, 63109