CVE-2015-4870 EXPLOIT
4.0
MEDIUM · CVSS 2.0 · EPSS 30.1% (pctl 98)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
Scoring
| CVSS | 4.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
| EPSS | 30.15% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-10-21 |
| Last modified | 2026-06-17 |
Affected (15)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| fedoraproject | fedora |
| mariadb | mariadb |
| opensuse | leap |
| opensuse | opensuse |
| oracle | linux |
| oracle | mysql |
| oracle | solaris |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | MySQL 5.5.45 - procedure analyse Function Denial of Service | 2016-05-30 |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177539.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00011.html
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00039.html
- http://packetstormsecurity.com/files/137232/MySQL-Procedure-Analyse-Denial-Of-Service.html
- http://rhn.redhat.com/errata/RHSA-2016-0534.html
- http://rhn.redhat.com/errata/RHSA-2016-0705.html
- http://rhn.redhat.com/errata/RHSA-2016-1480.html
- http://rhn.redhat.com/errata/RHSA-2016-1481.html
- http://www.debian.org/security/2015/dsa-3377
- http://www.debian.org/security/2015/dsa-3385
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/77208
- http://www.securitytracker.com/id/1033894
- http://www.ubuntu.com/usn/USN-2781-1
- https://access.redhat.com/errata/RHSA-2016:1132
- https://www.exploit-db.com/exploits/39867/
- https://www.suse.com/support/update/announcement/2016/suse-su-20160296-1.html
→ the Explorer · watch your stack · NVD