Executive brief
Oracle MySQL Server is a widely used database system for storing and managing corporate data. A vulnerability in the server's data definition component allows a low-privileged user to remotely cause the database to hang or crash. This can lead to a complete service outage, preventing applications and employees from accessing critical information.
Technical details
A vulnerability exists in the Server: DDL (Data Definition Language) subcomponent of Oracle MySQL Server. The flaw is classified as improper input validation (CWE-20) and is easily exploitable by a low-privileged attacker with network access via multiple protocols. Successful exploitation allows an attacker to cause a frequently repeatable crash or a complete hang of the MySQL Server process (mysqld), resulting in a total loss of availability. The issue affects versions 5.6.34 and earlier, and 5.7.16 and earlier. Patches were released by Oracle in the January 2017 Critical Patch Update.
Affected products
- Oracle MySQL Server 5.6.34 and earlier, 5.7.16 and earlier
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory
- 2017-09-21: patched: Red Hat released updated packages for Software Collections.