Junglewise Threat Intelligence

CVE-2017-3273: Oracle MySQL Server denial of service in DDL subcomponent

CVE-2017-3273 · Severity: medium · CVSS 6.5 · Published 2017-01-27

Technologies: Oracle MySQL Server. Vendors: Oracle.

Executive brief

Oracle MySQL Server is a widely used database system for storing and managing corporate data. A vulnerability in the server's data definition component allows a low-privileged user to remotely cause the database to hang or crash. This can lead to a complete service outage, preventing applications and employees from accessing critical information.

Technical details

A vulnerability exists in the Server: DDL (Data Definition Language) subcomponent of Oracle MySQL Server. The flaw is classified as improper input validation (CWE-20) and is easily exploitable by a low-privileged attacker with network access via multiple protocols. Successful exploitation allows an attacker to cause a frequently repeatable crash or a complete hang of the MySQL Server process (mysqld), resulting in a total loss of availability. The issue affects versions 5.6.34 and earlier, and 5.7.16 and earlier. Patches were released by Oracle in the January 2017 Critical Patch Update.

Affected products

  • Oracle MySQL Server 5.6.34 and earlier, 5.7.16 and earlier

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory
  • 2017-09-21: patched: Red Hat released updated packages for Software Collections.

References

Related threats