Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/C). Supported versions that are affected are 6.1.10 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. Note: The documentation has also been updated for the correct way to use mysql_stmt_close(). Please see: https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-execute.html, https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-fetch.html, https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-close.html, https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-error.html, https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-errno.html, and https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-sqlstate.html. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
References
Link | Resource |
---|---|
http://www.debian.org/security/2017/dsa-3922 | Third Party Advisory |
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/99730 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1038928 | Third Party Advisory VDB Entry |
http://www.debian.org/security/2017/dsa-3922 | Third Party Advisory |
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/99730 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1038928 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 03:25
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.debian.org/security/2017/dsa-3922 - Third Party Advisory | |
References | () http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/99730 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1038928 - Third Party Advisory, VDB Entry |
Information
Published : 2017-08-08 15:29
Updated : 2024-11-21 03:25
NVD link : CVE-2017-3635
Mitre link : CVE-2017-3635
CVE.ORG link : CVE-2017-3635
JSON object : View
Products Affected
oracle
- mysql_connector\/c
- mysql
debian
- debian_linux
CWE