First published: Wed Jan 18 2017(Updated: )
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets ). Supported versions that are affected are 5.5.53 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. External References: <a href="http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixMSQL">http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixMSQL</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mysql | <5.5.54 | 5.5.54 |
redhat/mariadb | <5.5.54 | 5.5.54 |
redhat/mariadb | <10.1.21 | 10.1.21 |
redhat/mariadb | <10.0.29 | 10.0.29 |
MySQL | >=5.5.0<=5.5.53 | |
Mariadb Mariadb | >=5.5.0<5.5.54 | |
Mariadb Mariadb | >=10.0.0<10.0.29 | |
Mariadb Mariadb | >=10.1.0<10.1.21 | |
Debian Debian Linux | =8.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux eus | =7.4 | |
redhat enterprise Linux eus | =7.5 | |
redhat enterprise Linux eus | =7.6 | |
redhat enterprise Linux eus | =7.7 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =7.6 | |
redhat enterprise Linux server aus | =7.7 | |
redhat enterprise Linux server tus | =7.6 | |
redhat enterprise Linux server tus | =7.7 | |
redhat enterprise Linux workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3243 is considered a difficult to exploit vulnerability that allows high privileged attackers with network access to compromise MySQL Server.
CVE-2017-3243 affects MySQL Server 5.5.53 and earlier versions.
To remediate CVE-2017-3243, you should upgrade to MySQL version 5.5.54 or later.
You may consider migrating to MariaDB versions 5.5.54, 10.0.29, or 10.1.21 to avoid CVE-2017-3243.
CVE-2017-3243 affects the MySQL Server component, specifically in the Charsets subcomponent.