Executive brief
A vulnerability in the replication component of Oracle MySQL Server can allow a low-privileged user to crash the database service. This affects the availability of the database, potentially leading to service outages and business disruption. Organizations using affected versions should apply the available security patches to ensure continuous operations.
Technical details
An unspecified vulnerability exists in the Server: Replication subcomponent of Oracle MySQL Server. The flaw is categorized as improper input validation (CWE-20) and is easily exploitable by a low-privileged attacker with network access via multiple protocols. A successful exploit allows the attacker to cause a complete denial of service (DoS) by repeatedly crashing or hanging the MySQL Server process. The vulnerability affects version 5.7.16 and earlier and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle MySQL Server 5.7.16 and earlier
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Oracle Critical Patch Update released