Junglewise Threat Intelligence

CVE-2017-3244: Oracle MySQL and MariaDB denial of service in DML subcomponent

CVE-2017-3244 · Severity: medium · CVSS 6.5 · Published 2017-01-27

Technologies: Oracle MySQL Server. Vendors: Oracle, MariaDB Foundation.

Executive brief

A vulnerability in the MySQL and MariaDB database servers could allow a user with low-level access to crash the database service. This type of attack results in a denial-of-service, making the database and any applications relying on it unavailable to users. Organizations using these database systems should apply the available security patches to ensure continuous service availability.

Technical details

This vulnerability affects the Data Manipulation Language (DML) subcomponent of the MySQL Server. It is classified as an 'easily exploitable' flaw that allows an authenticated, low-privileged attacker with network access via multiple protocols to impact the availability of the database. Successful exploitation results in a complete denial-of-service (DoS) by causing the server to hang or crash repeatedly. The issue was addressed in Oracle's January 2017 Critical Patch Update and corresponding updates for MariaDB and various Linux distributions. Root cause is attributed to insufficient information in the DML processing logic.

Affected products

  • Oracle MySQL Server 5.5.53 and earlier, 5.6.34 and earlier, 5.7.16 and earlier
  • MariaDB Foundation MariaDB 5.5.0 before 5.5.54, 10.0.0 before 10.0.29, 10.1.0 before 10.1.21

Timeline

  • 2017-01-19: advisory: Debian released DSA-3767-1 for mysql-5.5
  • 2017-01-22: advisory: Debian released DSA-3770-1 for mariadb-10.0
  • 2017-01-27: disclosed: NVD publication date

References

Related threats