Junglewise Threat Intelligence

CVE-2017-3251: Oracle MySQL Server denial of service in Optimizer

CVE-2017-3251 · Severity: medium · CVSS 4.9 · Published 2017-01-27

Technologies: Oracle Mysql, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability in the Optimizer component of Oracle MySQL Server allows a high-privileged user to remotely crash the database. This can lead to a complete denial of service, impacting business operations that rely on the database's availability. Successful exploitation results in a server hang or a repeatable crash, requiring administrative intervention to restore service.

Technical details

An unspecified vulnerability exists in the Server: Optimizer subcomponent of Oracle MySQL Server versions 5.7.16 and earlier. The flaw is easily exploitable by a high-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a hang or a frequently repeatable crash of the MySQL Server, resulting in a complete denial of service (DoS). The vulnerability was addressed in the Oracle Critical Patch Update for January 2017, with fixes included in MySQL version 5.7.17 and later.

Affected products

  • Oracle MySQL Server 5.7.16 and earlier

Timeline

  • 2017-01-27: advisory: Initial publication of CVE-2017-3251 by Oracle
  • 2017-10-12: patched: Red Hat released updates for rh-mysql57-mysql (5.7.19)

References

Related threats