Junglewise Threat Intelligence

CVE-2017-3317: Oracle MySQL and MariaDB denial of service in Logging component

CVE-2017-3317 · Severity: medium · CVSS 4 · Published 2017-01-27

Technologies: Oracle MySQL Server. Vendors: Oracle, MariaDB Foundation.

Executive brief

A vulnerability in the logging component of MySQL and MariaDB database servers can allow a high-privileged local user to cause a denial-of-service. An attacker with existing access to the underlying server infrastructure could cause the database to hang or crash repeatedly. This would disrupt business operations by making data unavailable to applications and users.

Technical details

This vulnerability exists in the Logging subcomponent of MySQL Server and MariaDB. It is classified as difficult to exploit, requiring a high-privileged attacker with local access to the infrastructure where the database executes. Exploitation requires human interaction from a person other than the attacker. A successful exploit results in a complete denial-of-service (DoS) by causing the server to hang or crash repeatedly. The issue has been addressed in MySQL versions 5.5.54, 5.6.35, and 5.7.17, as well as MariaDB versions 5.5.54, 10.0.29, and 10.1.21.

Affected products

  • Oracle MySQL Server 5.5.53 and earlier, 5.6.34 and earlier, 5.7.16 and earlier
  • MariaDB Foundation MariaDB 5.5.0 before 5.5.54, 10.0.0 before 10.0.29, 10.1.0 before 10.1.21

Timeline

  • 2017-01-17: advisory: Oracle Critical Patch Update (CPU) January 2017 released
  • 2017-01-19: patched: Debian released fixed mysql-5.5 packages
  • 2017-01-22: patched: Debian released fixed mariadb-10.0 packages
  • 2017-01-27: disclosed: NVD publication date

References

Related threats