Executive brief
A vulnerability in the Optimizer component of Oracle MySQL Server allows a high-privileged user to remotely crash the database. This can lead to a complete denial of service, impacting business operations that rely on the database's availability. Successful exploitation results in a server hang or a repeatable crash, requiring administrative intervention to restore service.
Technical details
An unspecified vulnerability exists in the Server: Optimizer subcomponent of Oracle MySQL Server versions 5.7.16 and earlier. The flaw is easily exploitable by a high-privileged attacker with network access via multiple protocols. Successful exploitation allows the attacker to cause a hang or a frequently repeatable crash of the MySQL Server, resulting in a complete denial of service (DoS). The vulnerability was addressed in the Oracle Critical Patch Update for January 2017, with fixes included in MySQL version 5.7.17 and later.
Affected products
- Oracle MySQL Server 5.7.16 and earlier
Timeline
- 2017-01-27: advisory: Initial publication of CVE-2017-3251 by Oracle
- 2017-10-12: patched: Red Hat released updates for rh-mysql57-mysql (5.7.19)