vendor:
MySQL
by:
Osanda Malith Jayathissa
7.5
CVSS
HIGH
Denial of Service (DoS)
20
CWE
Product Name: MySQL
Affected Version From: MySQL 5.5.0
Affected Version To: MySQL 5.5.45
Patch Exists: NO
Related CWE: CVE-2015-4870
CPE: a:mysql:mysql:5.5.45
Metasploit:
https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-4870/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2015-4870/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2015-4870/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2015-4870/, https://www.rapid7.com/db/vulnerabilities/oracle-mysql-cve-2015-4870/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2015-4870/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2015-4870/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2015-4870/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2015-4870/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-4870/
Platforms Tested:
2016
MySQL Procedure Analyse DoS Exploit
This exploit takes advantage of a vulnerability in the MySQL Procedure Analyse function, allowing an attacker to cause a Denial of Service (DoS) by sending a specially crafted payload. The vulnerability is identified by CVE-2015-4870.
Mitigation:
Upgrade MySQL to a version that has fixed this vulnerability. Apply any available patches or security updates.