Upstream information

CVE-2016-8288 at MITRE

Description

Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect integrity via vectors related to Server: InnoDB Plugin.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.9
Vector AV:N/AC:M/Au:S/C:N/I:P/A:P
Access Vector Network
Access Complexity Medium
Authentication Single
Confidentiality Impact None
Integrity Impact Partial
Availability Impact Partial
CVSS v3 Scores
  National Vulnerability Database
Base Score 3.1
Vector CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector Network
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact None
CVSSv3 Version 3
SUSE Bugzilla entry: 1005586 [RESOLVED / INVALID]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • libmysql56client18 >= 5.6.34-1.1
  • libmysql56client18-32bit >= 5.6.34-1.1
  • libmysql56client_r18 >= 5.6.34-1.1
  • libmysql56client_r18-32bit >= 5.6.34-1.1
  • mysql-community-server >= 5.6.34-1.1
  • mysql-community-server-bench >= 5.6.34-1.1
  • mysql-community-server-client >= 5.6.34-1.1
  • mysql-community-server-errormessages >= 5.6.34-1.1
  • mysql-community-server-test >= 5.6.34-1.1
  • mysql-community-server-tools >= 5.6.34-1.1
Patchnames:
openSUSE Tumbleweed GA libmysql56client18-32bit-5.6.34-1.1


SUSE Timeline for this CVE

CVE page created: Wed Oct 19 12:15:46 2016
CVE page last modified: Wed Oct 26 20:11:13 2022