5.3
CVSSv3

CVE-2017-3305

Published: 24/04/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6.3 | Impact Score: 6.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 561
Vector: AV:N/AC:M/Au:S/C:C/I:N/A:N

Vulnerability Summary

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and previous versions and 5.6.35 and previous versions. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue allows man-in-the-middle malicious users to hijack the authentication of users by leveraging incorrect ordering of security parameter verification in a client, aka, "The Riddle".

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql

debian debian linux 8.0

Vendor Advisories

Synopsis Important: rh-mysql56-mysql security and bug fix update Type/Severity Security Advisory: Important Topic An update for rh-mysql56-mysql is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Debian Bug report logs - #860544 Security fixes from the April 2017 CPU Package: src:mysql-55; Maintainer for src:mysql-55 is Debian MySQL Maintainers <pkg-mysql-maint@listsaliothdebianorg>; Reported by: "Norvald H Ryeng" <norvaldryeng@oraclecom> Date: Tue, 18 Apr 2017 11:30:01 UTC Severity: grave Tags: fixed ...
Debian Bug report logs - #854713 mysql-55: CVE-2017-3302: Use after free in libmysqlclientso Package: mysql-55; Maintainer for mysql-55 is Debian MySQL Maintainers <pkg-mysql-maint@listsaliothdebianorg>; Reported by: Balint Reczey <balint@balintreczeyhu> Date: Thu, 9 Feb 2017 18:33:07 UTC Severity: important ...
Several issues have been discovered in the MySQL database server The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5555, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly incompatible changes Please see the MySQL 55 Release Notes and Oracle's Critical Patch ...
Several security issues were fixed in MySQL ...
Several security issues were fixed in MySQL ...

Recent Articles

All ready for that Easter holiday? Here's a mild MySQL security bug
The Register • Shaun Nichols in San Francisco • 14 Apr 2017

Panic over the Riddle flaw – or just update to version 5.7. Your choice. We're not your dad

A programming blunder has been uncovered in Oracle's MySQL that can potentially leak usernames and passwords to man-in-the-middle eavesdroppers. Known as "The Riddle," the flaw potentially allows a miscreant to intercept and obtain login credentials sent from MySQL clients 5.5 and 5.6 to servers. Apparently, a fix introduced in versions 5.5.49 and 5.6.30 isn't enough to fully address the design flaw. Versions 5.7 and later, as well as MariaDB systems, are not vulnerable. According to security re...