Vulnerability CVE-2024-20977: Information

Description

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Published: Jan. 17, 2024
Modified: Feb. 2, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
MySQLsisyphus8.0.36-alt18.0.36-alt1ALT-PU-2024-1252-2338416Fixed
MySQLsisyphus_e2k8.0.36-alt18.0.36-alt1ALT-PU-2024-1905-1-Fixed
MySQLsisyphus_loongarch648.0.36-alt18.0.36-alt1ALT-PU-2024-1472-1-Fixed
MySQLp108.0.36-alt18.0.36-alt1ALT-PU-2024-1385-2338829Fixed
MySQLp10_e2k8.0.36-alt18.0.36-alt1ALT-PU-2024-2304-1-Fixed
MySQLc10f18.0.36-alt18.0.36-alt1ALT-PU-2024-2258-3340582Fixed
MySQLc9f28.0.36-alt0.c9.18.0.36-alt0.c9.1ALT-PU-2024-4030-3342752Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
Oracle Advisory
  • Patch
  • Vendor Advisory
https://security.netapp.com/advisory/ntap-20240201-0003/
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
      Start including
      8.0.0
      End including
      8.0.35

      cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
      Start including
      8.1.0
      End including
      8.2.0

      Configuration 2

      cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*