CVE-2017-3302: Use After Free

Published Feb 12, 2017
·
Updated

A use-after-free flaw was found in the MySQL client library (libmysqlclient.so). A malicious MySQL server could cause an application using the MySQL client library to crash.

Upstream bugs:

https://bugs.mysql.com/bug.php?id=70429 https://bugs.mysql.com/bug.php?id=63363

Upstream patch:

https://github.com/mysql/mysql-server/commit/4797ea0b772d5f4c5889bc552424132806f46e93

Other sources

Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3.

MITRE

Affected Software

22 affected componentsFixes available
redhat/mysql<5.5.55
5.5.55
redhat/mysql<5.6.21
5.6.21
redhat/mysql<5.7.5
5.7.5
redhat/mariadb<10.0.30
10.0.30
redhat/mariadb<10.1.22
10.1.22
redhat/mariadb<10.2.5
10.2.5
redhat/mariadb<5.5.55
5.5.55
Oracle MySQL>=5.6.0<5.6.21
Oracle MySQL>=5.7.0<5.7.5
MariaDB MariaDB<=5.5.54
MariaDB MariaDB>=10.0.0<=10.0.29
MariaDB MariaDB>=10.1.0<=10.1.21
MariaDB MariaDB>=10.2.0<=10.2.3
Debian Debian Linux=8.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Workstation=7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/mysql to a version that resolves this vulnerability.

    Fixed in 5.5.55
  2. Upgrade

    Upgrade redhat/mysql to a version that resolves this vulnerability.

    Fixed in 5.6.21
  3. Upgrade

    Upgrade redhat/mysql to a version that resolves this vulnerability.

    Fixed in 5.7.5
  4. Upgrade

    Upgrade redhat/mariadb to a version that resolves this vulnerability.

    Fixed in 10.0.30
  5. Upgrade

    Upgrade redhat/mariadb to a version that resolves this vulnerability.

    Fixed in 10.1.22
  6. Upgrade

    Upgrade redhat/mariadb to a version that resolves this vulnerability.

    Fixed in 10.2.5
  7. Upgrade

    Upgrade redhat/mariadb to a version that resolves this vulnerability.

    Fixed in 5.5.55
  8. Upgrade

    Upgrade Oracle MySQL to a version that resolves this vulnerability.

    Fixed in 5.6.21
  9. Upgrade

    Upgrade Oracle MySQL 5.7.x to a version that resolves this vulnerability.

    Fixed in 5.7.5
  10. Upgrade

    Upgrade MariaDB to a version that resolves this vulnerability.

    Fixed in 5.5.54
  11. Upgrade

    Upgrade MariaDB 10.0.x to a version that resolves this vulnerability.

    Fixed in 10.0.29
  12. Upgrade

    Upgrade MariaDB 10.1.x to a version that resolves this vulnerability.

    Fixed in 10.1.21
  13. Upgrade

    Upgrade MariaDB 10.2.x to a version that resolves this vulnerability.

    Fixed in 10.2.3

Event History

Feb 12, 2017
CVE Published
via MITRE·04:43 AM
Data Sourced
via MITRE·04:43 AM
DescriptionWeakness
Data Sourced
via NVD·04:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-3302?

CVE-2017-3302 has a high severity level due to the potential for application crashes caused by exploitation.

2

How do I fix CVE-2017-3302?

To resolve CVE-2017-3302, upgrade the MySQL client library to versions 5.5.55, 5.6.21, 5.7.5, or appropriate versions of MariaDB.

3

What types of applications are affected by CVE-2017-3302?

Applications using the affected MySQL client library (libmysqlclient.so) are vulnerable to CVE-2017-3302.

4

Who is vulnerable to CVE-2017-3302?

Vulnerable users include anyone running the specified versions of MySQL and MariaDB client libraries.

5

Can CVE-2017-3302 be exploited remotely?

Yes, a malicious MySQL server could exploit CVE-2017-3302 to crash applications remotely.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203