CVE-2019-2503

Source
https://cve.org/CVERecord?id=CVE-2019-2503
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-2503.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-2503
Downstream
Related
Published
2019-01-16T19:30:34.610Z
Modified
2026-07-17T21:00:33.166460940Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handling). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.4 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H).

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "7.3"
                },
                {
                    "introduced": "9.5"
                }
            ],
            "vendor_product": "netapp:active_iq_unified_manager",
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*",
                "cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "16.04"
                },
                {
                    "last_affected": "16.04"
                },
                {
                    "introduced": "18.04"
                },
                {
                    "last_affected": "18.04"
                },
                {
                    "introduced": "18.10"
                },
                {
                    "last_affected": "18.10"
                }
            ],
            "vendor_product": "canonical:ubuntu_linux",
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
                "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
                "cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "7.0"
                },
                {
                    "last_affected": "7.0"
                },
                {
                    "introduced": "8.0"
                },
                {
                    "last_affected": "8.0"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_desktop",
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_desktop:8.0:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "8.1"
                },
                {
                    "last_affected": "8.1"
                },
                {
                    "introduced": "8.2"
                },
                {
                    "last_affected": "8.2"
                },
                {
                    "introduced": "8.4"
                },
                {
                    "last_affected": "8.4"
                },
                {
                    "introduced": "8.6"
                },
                {
                    "last_affected": "8.6"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_eus",
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "7.0"
                },
                {
                    "last_affected": "7.0"
                },
                {
                    "introduced": "8.0"
                },
                {
                    "last_affected": "8.0"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_server",
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_server:8.0:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "8.2"
                },
                {
                    "last_affected": "8.2"
                },
                {
                    "introduced": "8.4"
                },
                {
                    "last_affected": "8.4"
                },
                {
                    "introduced": "8.6"
                },
                {
                    "last_affected": "8.6"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_server_aus",
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "8.2"
                },
                {
                    "last_affected": "8.2"
                },
                {
                    "introduced": "8.4"
                },
                {
                    "last_affected": "8.4"
                },
                {
                    "introduced": "8.6"
                },
                {
                    "last_affected": "8.6"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_server_tus",
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "7.0"
                },
                {
                    "last_affected": "7.0"
                },
                {
                    "introduced": "8.0"
                },
                {
                    "last_affected": "8.0"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_workstation",
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_workstation:8.0:*:*:*:*:*:*:*"
            ]
        }
    ]
}
References

Affected packages

Git / github.com/mariadb/server

Affected ranges

Type
GIT
Repo
https://github.com/mariadb/server
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "5.5.0"
        },
        {
            "fixed": "5.5.62"
        },
        {
            "introduced": "10.0.0"
        },
        {
            "fixed": "10.0.37"
        },
        {
            "introduced": "10.1.0"
        },
        {
            "fixed": "10.1.36"
        },
        {
            "introduced": "10.2.0"
        },
        {
            "fixed": "10.2.18"
        },
        {
            "introduced": "10.3.0"
        },
        {
            "fixed": "10.3.10"
        }
    ],
    "cpe": "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

mariadb-10.*
mariadb-10.1.0
mariadb-10.1.10
mariadb-10.1.11
mariadb-10.1.12
mariadb-10.1.13
mariadb-10.1.14
mariadb-10.1.15
mariadb-10.1.16
mariadb-10.1.17
mariadb-10.1.18
mariadb-10.1.19
mariadb-10.1.2
mariadb-10.1.20
mariadb-10.1.21
mariadb-10.1.22
mariadb-10.1.23
mariadb-10.1.24
mariadb-10.1.25
mariadb-10.1.26
mariadb-10.1.27
mariadb-10.1.28
mariadb-10.1.29
mariadb-10.1.3
mariadb-10.1.30
mariadb-10.1.31
mariadb-10.1.32
mariadb-10.1.33
mariadb-10.1.34
mariadb-10.1.35
mariadb-10.1.4
mariadb-10.1.5
mariadb-10.1.6
mariadb-10.1.7
mariadb-10.1.8
mariadb-10.1.9
mariadb-10.2.0
mariadb-10.2.1
mariadb-10.2.10
mariadb-10.2.11
mariadb-10.2.12
mariadb-10.2.13
mariadb-10.2.14
mariadb-10.2.15
mariadb-10.2.16
mariadb-10.2.2
mariadb-10.2.5
mariadb-10.3.0
mariadb-10.3.1
mariadb-10.3.2
mariadb-10.3.4
mariadb-10.3.5
mariadb-10.3.6
mariadb-10.3.7

Database specific

vanir_signatures
[
    {
        "target": {
            "file": "mysys/mf_iocache2.c"
        },
        "id": "CVE-2019-2503-31d9682c",
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/mariadb/server/commit/bac287c315b1792e7ae33f91add6a60292f9bae8",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "160075039351122944864225182554874669088",
                "79298247766313756764199076124200846221",
                "45115464249083926102003093201691213873",
                "234850493844753889546639429561578022423",
                "28144202877714812540506170033579428584",
                "64207172708277179404454160631042475789",
                "237722189373658064007831416036979490253",
                "40893712863390563503154152743217547031",
                "117668516850458519561463813363427354257",
                "157614703768094946194775545036620441701",
                "15967427616295603339113842507058398295",
                "104723310754908331401965919169681994802",
                "128841576046909535802914848653453387150",
                "284907253619130800196406482515430948114",
                "58255352786302269574555313408484604557",
                "157514477970302582442983000214658193991",
                "49411501730675364796830781016823824091",
                "156754744226265852277547691043485091575",
                "151934133497638100292742275943448330976",
                "10181848583206569474669288713374153883",
                "247129231873868569546561042046461048482"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "sql/sql_truncate.cc",
            "function": "Sql_cmd_truncate_table::truncate_table"
        },
        "id": "CVE-2019-2503-72121355",
        "signature_type": "Function",
        "deprecated": false,
        "source": "https://github.com/mariadb/server/commit/bad2f1569da57c4a81cc84ec2f4a79924df9c8d6",
        "signature_version": "v1",
        "digest": {
            "function_hash": "308253576018065477432791791193588044020",
            "length": 1331.0
        }
    },
    {
        "target": {
            "file": "sql/sql_truncate.cc"
        },
        "id": "CVE-2019-2503-ed6762dc",
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/mariadb/server/commit/bad2f1569da57c4a81cc84ec2f4a79924df9c8d6",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "233329946525851308164343744210653883501",
                "204742638511364347075405366020716870838",
                "164974133903162645092052012131298403240"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "sql/sql_class.h"
        },
        "id": "CVE-2019-2503-f33e8bff",
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/mariadb/server/commit/bad2f1569da57c4a81cc84ec2f4a79924df9c8d6",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "284485189603290621779676875043266591403",
                "132605580046284372650070224531900132128",
                "302718530449704346344600505888277165066",
                "55767056226081983856624214715648615778"
            ],
            "threshold": 0.9
        }
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-2503.json"
vanir_signatures_modified
"2026-07-09T05:09:54Z"

Git / github.com/mysql/mysql-server

Affected ranges

Type
GIT
Repo
https://github.com/mysql/mysql-server
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Introduced
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "5.6.0"
        },
        {
            "last_affected": "5.6.42"
        },
        {
            "introduced": "5.7.0"
        },
        {
            "last_affected": "5.7.24"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "last_affected": "8.0.13"
        }
    ],
    "cpe": "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

mysql-3.*
mysql-3.23.22-beta
mysql-3.23.28-gamma
mysql-3.23.30-gamma
mysql-3.23.31
mysql-3.23.32
mysql-3.23.33
mysql-3.23.36
mysql-4.*
mysql-4.0.2
mysql-4.0.4
mysql-5.*
mysql-5.1.4
mysql-5.6.40
mysql-5.6.42
mysql-5.7.24
mysql-8.*
mysql-8.0.13

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-2503.json"