CVE编号
CVE-2020-2570利用情况
暂无补丁情况
官方补丁披露时间
2020-01-16漏洞描述
Oracle MySQL的MySQL客户端产品中的漏洞(组件:C API)。受影响的受支持版本是5.7.28和更低版本以及8.0.18和更低版本。难以利用的漏洞允许未经身份验证的攻击者通过多种协议进行网络访问,从而危害MySQL客户端。成功攻击此漏洞可能导致未经授权的能力导致MySQL客户端挂起或频繁重复发生的崩溃(完整的DOS)。 CVSS 3.0基本分数5.9(可用性影响)。 CVSS矢量:(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)。解决建议
厂商已发布了漏洞修复程序,请及时关注更新:https://www.oracle.com/security-alerts/cpujan2020.html
参考链接 |
|
---|---|
https://security.gentoo.org/glsa/202105-27 | |
https://usn.ubuntu.com/4250-1/ | |
https://www.oracle.com/security-alerts/cpujan2020.html |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | oracle | mysql | * |
From (including) 5.7.0 |
Up to (including) 5.7.28 |
||||
运行在以下环境 | |||||||||
应用 | oracle | mysql | * |
From (including) 8.0.0 |
Up to (including) 8.0.18 |
||||
运行在以下环境 | |||||||||
系统 | alibaba_cloud_linux_2.1903 | qemu | * |
Up to (excluding) 4.19.91-22.al7 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.10 | qemu | * |
Up to (excluding) 2.4.48-r2 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.11 | qemu | * |
Up to (excluding) 2.4.48-r3 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.12 | qemu | * |
Up to (excluding) 2.4.50-r1 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.13 | qemu | * |
Up to (excluding) 2.4.56-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.9 | qemu | * |
Up to (excluding) 2.4.48-r2 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_edge | qemu | * |
Up to (excluding) 2.4.56-r0 |
|||||
运行在以下环境 | |||||||||
系统 | amazon linux_2 | qemu | * |
Up to (excluding) 4.14.209-160.335.amzn2 |
|||||
运行在以下环境 | |||||||||
系统 | amazon linux_AMI | qemu | * |
Up to (excluding) 4.14.209-117.337.amzn1 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_2 | qemu | * |
Up to (excluding) 3.1.0-8.amzn2.0.8 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_AMI | qemu | * |
Up to (excluding) 4.14.209-117.337.amzn1 |
|||||
运行在以下环境 | |||||||||
系统 | centos_7 | qemu | * |
Up to (excluding) 3.10.0-1160.21.1.el7 |
|||||
运行在以下环境 | |||||||||
系统 | centos_8 | qemu | * |
Up to (excluding) 0.9.11-17.el8 |
|||||
运行在以下环境 | |||||||||
系统 | debian_10 | qemu | * |
Up to (excluding) 0.9.11+dfsg-1.3+deb10u4 |
|||||
运行在以下环境 | |||||||||
系统 | debian_11 | qemu | * |
Up to (excluding) 2.4.55+dfsg-1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | qemu | * |
Up to (excluding) 4.9.246-1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_sid | qemu | * |
Up to (excluding) 5.7.26-1 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_32 | qemu | * |
Up to (excluding) 3.8.6-1.fc32 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_33 | qemu | * |
Up to (excluding) 3.9.3-1.fc33 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.1 | qemu | * |
Up to (excluding) 2.4.46-lp151.10.24.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.2 | qemu | * |
Up to (excluding) 2.4.46-lp152.14.15.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.3 | qemu | * |
Up to (excluding) 5.2.0-17.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle linux_6 | qemu | * |
Up to (excluding) 4.1.12-124.46.3.el6uek |
|||||
运行在以下环境 | |||||||||
系统 | oracle linux_7 | qemu | * |
Up to (excluding) 4.14.35-2025.404.1.1.el7 |
|||||
运行在以下环境 | |||||||||
系统 | oracle linux_8 | qemu | * |
Up to (excluding) 5.4.17-2036.102.0.2.el8 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_6 | qemu | * |
Up to (excluding) 4.1.12-124.46.3.el7uek |
|||||
运行在以下环境 | |||||||||
系统 | oracle_7 | qemu | * |
Up to (excluding) 5.4.17-2036.102.0.2.el7 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_8 | qemu | * |
Up to (excluding) 0.9.11-17.el8 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_7 | bpftool | * |
Up to (excluding) 0:3.10.0-1160.21.1.el7 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_7 | kernel-rt | * |
Up to (excluding) 0:3.10.0-1160.21.1.rt56.1158.el7 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_8 | qemu | * |
Up to (excluding) 0.9.11-17.el8 |
|||||
运行在以下环境 | |||||||||
系统 | sles_12_SP5 | qemu | * |
Up to (excluding) 0.9.9-17.34.1 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12_SP5 | qemu | * |
Up to (excluding) 4.12.14-16.38.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04_lts | linux-aws | * |
Up to (excluding) 4.4.0-1082.86 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04_lts | linux-azure | * |
Up to (excluding) 4.15.0-1106.118~14.04.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04_lts | openldap | * |
Up to (excluding) 2.4.31-1+nmu2ubuntu8.5+esm4 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04 | qemu | * |
Up to (excluding) 5.7.29-0ubuntu0.16.04.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04_lts | libvncserver | * |
Up to (excluding) 0.9.10+dfsg-3ubuntu0.16.04.6 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04_lts | linux | * |
Up to (excluding) 4.2.0-16.19 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04_lts | linux | * |
Up to (excluding) 4.4.0-197.229 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04_lts | mysql-5.7 | * |
Up to (excluding) 5.7.29-0ubuntu0.16.04.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04_lts | openldap | * |
Up to (excluding) 2.4.42+dfsg-2ubuntu3.11 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04 | qemu | * |
Up to (excluding) 5.7.29-0ubuntu0.18.04.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04_lts | libvncserver | * |
Up to (excluding) 0.9.11+dfsg-1ubuntu1.4 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04_lts | linux | * |
Up to (excluding) 4.15.0-129.132 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04_lts | linux | * |
Up to (excluding) 4.15.0-135.139 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04_lts | mysql-5.7 | * |
Up to (excluding) 5.7.29-0ubuntu0.18.04.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04_lts | openldap | * |
Up to (excluding) 2.4.45+dfsg-1ubuntu1.8 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_20.04 | qemu | * |
Up to (excluding) 8.0.19-0ubuntu2 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_21.04 | qemu | * |
Up to (excluding) 8.0.19-0ubuntu2 |
|||||
- 攻击路径 远程
- 攻击复杂度 困难
- 权限要求 无需权限
- 影响范围 有限影响
- EXP成熟度 未验证
- 补丁情况 官方补丁
- 数据保密性 无影响
- 数据完整性 无影响
- 服务器危害 无影响
- 全网数量 100
还没有评论,来说两句吧...