ubuntu · CVE-2018-3145

Quick triage

Priority: medium Published: 2018-10-17 01:31:00 UTC Updated: 2025-08-25 22:53:58 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-3145 medium priority: Ubuntu including 10 source packages (mariadb-10.0, mariadb-10.1, …), 120 status rows across 13 suites (bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, trusty, upstream, vivid, xenial): DNE 94, not-affected 22, needs-triage 4.

Description:

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

cvelogic Threat Intelligence