CVE-2018-3284: Medium severity Oracle MySQL vulnerability
Last updated 25 August 2025
Other sources
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
— Red Hat
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this MySQL Server vulnerability?
The vulnerability ID for this MySQL Server vulnerability is CVE-2018-3284.
Which versions of MySQL Server are affected by this vulnerability?
The versions of MySQL Server that are affected by this vulnerability are 5.7.23 and prior, and 8.0.12 and prior.
Is it difficult to exploit this vulnerability?
Yes, this vulnerability is difficult to exploit.
Can a high privileged attacker compromise the MySQL Server through this vulnerability?
Yes, a high privileged attacker with network access can compromise the MySQL Server through this vulnerability.
How can I fix this vulnerability?
To fix this vulnerability, update to MySQL Server version 5.7.24 or later for versions 5.7.x, and update to version 8.0.13 or later for versions 8.0.x.