Junglewise Threat Intelligence

CVE-2017-3243: Oracle MySQL and MariaDB denial of service in Charsets component

CVE-2017-3243 · Severity: medium · CVSS 4.4 · Published 2017-01-27

Technologies: Oracle MySQL Server. Vendors: MariaDB Foundation, Oracle.

Executive brief

A vulnerability in the MySQL and MariaDB database servers could allow a high-privileged user to cause a complete denial of service. By exploiting a flaw in the character set handling component, an attacker can cause the database to hang or crash repeatedly. This impacts the availability of applications and services that rely on these databases for data storage and retrieval.

Technical details

A vulnerability exists in the 'Server: Charsets' subcomponent of Oracle MySQL and MariaDB. It is classified as a denial of service (DoS) vulnerability that is difficult to exploit. A high-privileged attacker with network access via multiple protocols can trigger a hang or a frequently repeatable crash of the MySQL Server. The issue affects MySQL versions 5.5.53 and earlier, as well as several MariaDB versions. Patches were released in MySQL 5.5.54 and MariaDB 10.0.29 and 10.1.21.

Affected products

  • Oracle MySQL Server 5.5.53 and earlier
  • MariaDB Foundation MariaDB 5.5.0 to 5.5.53, 10.0.0 to 10.0.28, 10.1.0 to 10.1.20

Timeline

  • 2017-01-17: advisory: Oracle Critical Patch Update (CPU) released
  • 2017-01-19: patched: Debian released fixed mysql-5.5 packages
  • 2017-01-27: disclosed: NVD publication date

References

Related threats