Bug 1774049 (CVE-2019-2920)

Summary: CVE-2019-2920 mysql-connector-odbc: An unauthenticated attacker with network access can, via multiple protocols compromise MySQL Connectors
Product: [Other] Security Response Reporter: Marian Rehak <mrehak>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: databases-maint, dciabrin, fjanus, hhorak, ljavorsk, mbayer, mmuzila, mschorm, praiskup, SpikeFedora, tgl
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: mysql-connector-odbc 5.3.14, mysql-connector-odbc 8.0.18 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-27 10:55:37 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1774487, 1790927    
Bug Blocks: 1774498    

Description Marian Rehak 2019-11-19 13:39:24 UTC
An unauthenticated attacker with network access can, via multiple protocols compromise MySQL Connectors. Successful attacks of this vulnerability can result in a partial denial of service of MySQL Connectors.
Affected versions are 5.3.13 and prior and 8.0.17 and prior.

Comment 1 Marian Rehak 2019-11-19 13:40:12 UTC
Created community-mysql tracking bugs for this issue:

Affects: fedora-all [bug 1774056]


Created mariadb tracking bugs for this issue:

Affects: fedora-all [bug 1774050]


Created mariadb:10.1/mariadb tracking bugs for this issue:

Affects: fedora-29 [bug 1774053]


Created mariadb:10.3/mariadb tracking bugs for this issue:

Affects: fedora-all [bug 1774051]


Created mariadb:10.4/mariadb tracking bugs for this issue:

Affects: fedora-all [bug 1774052]


Created mysql:5.6/community-mysql tracking bugs for this issue:

Affects: fedora-30 [bug 1774057]


Created mysql:5.7/community-mysql tracking bugs for this issue:

Affects: fedora-all [bug 1774055]


Created mysql:8.0/community-mysql tracking bugs for this issue:

Affects: fedora-all [bug 1774054]

Comment 2 Marian Rehak 2019-11-20 12:03:31 UTC
Created mysql-connector-odbc tracking bugs for this issue:

Affects: fedora-all [bug 1774487]

Comment 3 Marian Rehak 2019-11-20 12:04:44 UTC
External Reference:

https://www.oracle.com/security-alerts/cpuoct2019.html