CVE-2017-3647

medium
Published 2017-08-08 Β· Modified 2026-05-13
CVSS v3
4.4
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
4.4

Description

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

Predictions

Exploit likelihood
54%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description mysql: Server: Replication unspecified vulnerability (CPU Jul 2017) CVSS v3: 4.4 (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Software Collections for Red Hat Enterprise Linux 6rh-mysql56-mysql-0:5.6.37-5.el6RHSA-2017:27872017-09-21T00:00:00Z Red Hat Software Collections for Red Hat Enterprise Linux…

Description

mysql: Server: Replication unspecified vulnerability (CPU Jul 2017)

CVSS v3: 4.4 (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-mysql56-mysql-0:5.6.37-5.el6RHSA-2017:27872017-09-21T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-mysql57-mysql-0:5.7.19-6.el6RHSA-2017:28862017-10-12T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-mysql56-mysql-0:5.6.37-5.el6RHSA-2017:27872017-09-21T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-mysql57-mysql-0:5.7.19-6.el6RHSA-2017:28862017-10-12T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mysql56-mysql-0:5.6.37-5.el7RHSA-2017:27872017-09-21T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mysql57-mysql-0:5.7.19-6.el7RHSA-2017:28862017-10-12T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSrh-mysql56-mysql-0:5.6.37-5.el7RHSA-2017:27872017-09-21T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSrh-mysql57-mysql-0:5.7.19-6.el7RHSA-2017:28862017-10-12T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 5mysql55-mysqlNot affected
Red Hat Enterprise Linux 6mysqlNot affected
Red Hat Enterprise Linux 7mariadbNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)mariadb-galeraNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)mariadb-galeraNot affected
Red Hat OpenStack Platform 10 (Newton)mariadb-galeraNot affected
Red Hat OpenStack Platform 11 (Ocata)mariadb-galeraNot affected
Red Hat OpenStack Platform 12 (Pike)mariadb-galeraNot affected
Red Hat OpenStack Platform 8 (Liberty)mariadb-galeraNot affected
Red Hat OpenStack Platform 9 (Mitaka)mariadb-galeraNot affected
Red Hat Software Collectionsrh-mariadb100-mariadbNot affected
Red Hat Software Collectionsrh-mariadb101-mariadbNot affected
Red Hat Software Collectionsrh-mariadb102-mariadbNot affected

Apply commands

bash fix
Apply RHSA-2017:2787 for Red Hat Software Collections for Red Hat Enterprise Linux 6
yum update -y rh-mysql56-mysql
# or:
dnf upgrade -y rh-mysql56-mysql

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 5Not affected
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux OpenStack Platform 6 (Juno)Not affected
redhatRed Hat Enterprise Linux OpenStack Platform 7 (Kilo)Not affected
redhatRed Hat OpenStack Platform 10 (Newton)Not affected
redhatRed Hat OpenStack Platform 11 (Ocata)Not affected
redhatRed Hat OpenStack Platform 12 (Pike)Not affected
redhatRed Hat OpenStack Platform 8 (Liberty)Not affected
redhatRed Hat OpenStack Platform 9 (Mitaka)Not affected
redhatRed Hat Software CollectionsNot affected
redhatRed Hat Software CollectionsNot affected
redhatRed Hat Software CollectionsNot affected

OS impact

OSVersionStatusFixed in
suse slesaffected

Application impact

VendorProductVersionsFixed
oracle oraclemysql{"startIncluding":"5.6.0","endIncluding":"5.6.36"}
oracle oraclemysql{"startIncluding":"5.7.0","endIncluding":"5.7.18"}

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.