CVE-2017-3309: High severity Oracle MySQL vulnerability
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).
Other sources
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html#AppendixMSQL
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 5.5.55 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 5.6.36 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 5.7.18 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 5.5.55 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.2.6 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.1.23 - Upgrade
Upgrade
redhat/mariadbto a version that resolves this vulnerability.Fixed in 10.0.31 - Upgrade
Upgrade
Oracle MySQL Server (Server: Optimizer)to a version that resolves this vulnerability.Fixed in 5.5.55 - Upgrade
Upgrade
Oracle MySQL Server (Server: Optimizer)to a version that resolves this vulnerability.Fixed in 5.6.36 - Upgrade
Upgrade
Oracle MySQL Server (Server: Optimizer)to a version that resolves this vulnerability.Fixed in 5.7.18
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3309?
CVE-2017-3309 is classified as an easily exploitable vulnerability in MySQL Server that affects low privileged attackers.
How do I fix CVE-2017-3309?
To remediate CVE-2017-3309, upgrade your MySQL installation to versions 5.5.55, 5.6.36, or 5.7.18 and later.
Which versions of MySQL are affected by CVE-2017-3309?
Affected MySQL versions include 5.5.54 and earlier, 5.6.35 and earlier, and 5.7.17 and earlier.
Can MariaDB installations be impacted by CVE-2017-3309?
Yes, MariaDB versions prior to 5.5.55, 10.1.23, 10.0.31, and 10.2.6 can also be affected.
Is there a workaround for CVE-2017-3309?
There is no specific workaround for CVE-2017-3309, updating to the fixed versions is the recommended solution.