Executive brief
A vulnerability in the encryption subcomponent of Oracle MySQL Server can allow a low-privileged user to crash the database service. This issue affects organizations using MySQL versions 5.6 and 5.7 for data storage and management. A successful exploit results in a complete denial of service, potentially halting business operations that rely on the database, though it requires interaction from a person other than the attacker.
Technical details
A vulnerability exists in the 'Server: Security: Encryption' subcomponent of Oracle MySQL Server (versions 5.6.34/5.7.16 and earlier). The flaw is classified as easily exploitable by a low-privileged attacker with network access via multiple protocols. Exploitation requires human interaction from a user other than the attacker (UI:R) and has a scope impact (S:C), meaning the vulnerability in MySQL can affect additional products. The primary impact is on availability, where an attacker can cause a complete Denial of Service (DoS) through a hang or repeatable crash. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle MySQL Server 5.6.34 and earlier, 5.7.16 and earlier
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update