CVE-2017-3599

Scores

EPSS

0.873high87.3%
0%20%40%60%80%100%

Percentile: 87.3%

CVSS

7.5high3.x
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 3.x
7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS 2.0
7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Description

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily “exploitable” vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue is an integer overflow in sql/auth/sql_authentication.cc which allows remote attackers to cause a denial of service via a crafted authentication packet.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

CWEs

CWE-190

Related Vulnerabilities

Exploits

Exploit ID: 41954

Source: exploitdb

URL: https://www.exploit-db.com/exploits/41954

Exploit ID: CVE-2017-3599

Source: github-poc

URL: https://github.com/SECFORCE/CVE-2017-3599

Vulnerable Software (47)

Type: Configuration

Product: mariadb-10.0

Operating System: ubuntu xenial 16.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: mariadb-10.0

Operating System: ubuntu yakkety 16.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: mariadb-10.1

Operating System: ubuntu artful 17.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: mariadb-10.1

Operating System: ubuntu bionic 18.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: mariadb-10.1

Operating System: ubuntu cosmic 18.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: mariadb-10.1

Operating System: ubuntu zesty 17.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: mariadb-5.5

Operating System: ubuntu trusty 14.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: mysql-5.5

Operating System: debian

Trait:
{  "unaffected": true}

Source: debian

Type: Configuration

Product: mysql-5.5

Operating System: ubuntu trusty 14.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: mysql-5.6

Operating System: ubuntu trusty 14.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: mysql-5.7

Operating System: debian

Trait:
{  "fixed": "5.7.18-1"}

Source: debian

Type: Configuration

Product: mysql-5.7

Operating System: ubuntu artful 17.10

Trait:
{  "fixed": "5.7.18-0ubuntu1"}

Source: ubuntu

Type: Configuration

Product: mysql-5.7

Operating System: ubuntu bionic 18.04

Trait:
{  "fixed": "5.7.18-0ubuntu1"}

Source: ubuntu

Type: Configuration

Product: mysql-5.7

Operating System: ubuntu cosmic 18.10

Trait:
{  "fixed": "5.7.18-0ubuntu1"}

Source: ubuntu

Type: Configuration

Product: mysql-5.7

Operating System: ubuntu disco 19.04

Trait:
{  "fixed": "5.7.18-0ubuntu1"}

Source: ubuntu

Type: Configuration

Product: mysql-5.7

Operating System: ubuntu xenial 16.04

Trait:
{  "fixed": "5.7.18-0ubuntu0.16.04.1"}

Source: ubuntu

Type: Configuration

Product: mysql-5.7

Operating System: ubuntu yakkety 16.10

Trait:
{  "fixed": "5.7.18-0ubuntu0.16.10.1"}

Source: ubuntu

Type: Configuration

Product: mysql-5.7

Operating System: ubuntu zesty 17.04

Trait:
{  "fixed": "5.7.18-0ubuntu0.17.04.1"}

Source: ubuntu

Type: Configuration

Product: mysql-8.0

Operating System: ubuntu eoan 19.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: mysql-8.0

Operating System: ubuntu hirsute 21.04

Trait:
{  "unaffected": true}

Source: ubuntu