CVE-2017-3599
An integer overflow flaw leading to a buffer overflow was found in the way MySQL parsed connection handshake packets. An unauthenticated remote attacker with access to the MySQL port could use this flaw to crash the mysqld daemon.
Find out more about CVE-2017-3599 from the MITRE CVE dictionary dictionary and NIST NVD.
CVSS v3 metrics
| CVSS3 Base Score | 7.5 |
|---|---|
| CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity Impact | None |
| Availability Impact | High |
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Software Collections for Red Hat Enterprise Linux 6 (rh-mysql56-mysql) | RHSA-2017:2787 | 2017-09-21 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 (rh-mysql56-mysql) | RHSA-2017:2787 | 2017-09-21 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 (rh-mysql57-mysql) | RHSA-2017:2886 | 2017-10-12 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 (rh-mysql57-mysql) | RHSA-2017:2886 | 2017-10-12 |
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat Software Collections for Red Hat Enterprise Linux | rh-mariadb101-mariadb | Not affected |
| Red Hat Software Collections for Red Hat Enterprise Linux | rh-mariadb100-mariadb | Not affected |
| Red Hat OpenStack Platform 9.0 | mariadb-galera | Not affected |
| Red Hat OpenStack Platform 8.0 (Liberty) | mariadb-galera | Not affected |
| Red Hat OpenStack Platform 12.0 | mariadb-galera | Not affected |
| Red Hat OpenStack Platform 11.0 (Ocata) | mariadb-galera | Not affected |
| Red Hat OpenStack Platform 10 | mariadb-galera | Not affected |
| Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | mariadb-galera | Not affected |
| Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | mariadb-galera | Not affected |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) | mariadb-galera | Not affected |
| Red Hat Enterprise Linux 7 | mariadb | Not affected |
| Red Hat Enterprise Linux 6 | mysql | Not affected |
| Red Hat Enterprise Linux 5 | mysql55-mysql | Not affected |
