Junglewise Threat Intelligence

CVE-2016-8327: Oracle MySQL Server denial of service in Replication subcomponent

CVE-2016-8327 · Severity: medium · CVSS 4.4 · Published 2017-01-27

Technologies: Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the replication component of Oracle MySQL Server could allow a highly privileged user to disrupt database services. If exploited, an attacker can cause the database to hang or crash repeatedly, leading to a complete denial of service. This impact can halt business operations that rely on the database for data storage and retrieval.

Technical details

An unspecified vulnerability exists in the Server: Replication subcomponent of Oracle MySQL Server versions 5.6.34 and earlier and 5.7.16 and earlier. The flaw is categorized as difficult to exploit and requires a high-privileged attacker with network access via multiple protocols. A successful exploit allows the attacker to cause a complete denial of service (DoS) by triggering a hang or a frequently repeatable crash of the MySQL Server process. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle MySQL Server 5.6.34 and earlier, 5.7.16 and earlier

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats