Executive brief
A vulnerability in the logging component of MySQL and MariaDB database servers can allow a high-privileged local user to cause a denial-of-service. An attacker with existing access to the underlying server infrastructure could cause the database to hang or crash repeatedly. This would disrupt business operations by making data unavailable to applications and users.
Technical details
This vulnerability exists in the Logging subcomponent of MySQL Server and MariaDB. It is classified as difficult to exploit, requiring a high-privileged attacker with local access to the infrastructure where the database executes. Exploitation requires human interaction from a person other than the attacker. A successful exploit results in a complete denial-of-service (DoS) by causing the server to hang or crash repeatedly. The issue has been addressed in MySQL versions 5.5.54, 5.6.35, and 5.7.17, as well as MariaDB versions 5.5.54, 10.0.29, and 10.1.21.
Affected products
- Oracle MySQL Server 5.5.53 and earlier, 5.6.34 and earlier, 5.7.16 and earlier
- MariaDB Foundation MariaDB 5.5.0 before 5.5.54, 10.0.0 before 10.0.29, 10.1.0 before 10.1.21
Timeline
- 2017-01-17: advisory: Oracle Critical Patch Update (CPU) January 2017 released
- 2017-01-19: patched: Debian released fixed mysql-5.5 packages
- 2017-01-22: patched: Debian released fixed mariadb-10.0 packages
- 2017-01-27: disclosed: NVD publication date
References
- http://www.debian.org/security/2017/dsa-3767
- http://www.debian.org/security/2017/dsa-3770
- http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html
- http://www.securityfocus.com/bid/95585
- http://www.securitytracker.com/id/1037640
- https://access.redhat.com/errata/RHSA-2017:2192
- https://access.redhat.com/errata/RHSA-2017:2787