Executive brief
A vulnerability in the replication component of Oracle MySQL Server could allow a highly privileged user to disrupt database services. If exploited, an attacker can cause the database to hang or crash repeatedly, leading to a complete denial of service. This impact can halt business operations that rely on the database for data storage and retrieval.
Technical details
An unspecified vulnerability exists in the Server: Replication subcomponent of Oracle MySQL Server versions 5.6.34 and earlier and 5.7.16 and earlier. The flaw is categorized as difficult to exploit and requires a high-privileged attacker with network access via multiple protocols. A successful exploit allows the attacker to cause a complete denial of service (DoS) by triggering a hang or a frequently repeatable crash of the MySQL Server process. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle MySQL Server 5.6.34 and earlier, 5.7.16 and earlier
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published