Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-3599

Quick assessment

Affected
n/a n/a
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Oracle MySQL Server是美国甲骨文(Oracle)公司的一套开源的关系数据库管理系统。该数据库系统具有性能高、成本低、可靠性好等特点。 Oracle MySQL中的MySQL Server组件的Server: Pluggable Auth子组件存在安全漏洞。攻击者可利用该漏洞造成服务器拒绝服务(挂起和频繁崩溃),影响数据的可用性。以下版本受到影响:Oracle MySQL 5.6.35及之前的版本,5.7.17及之前的版本。

AI Predicted 7.5 Difficulty: Easy EPSS 89.92% · P100

Public Exploits 1

ExploitDB · 1 EDB-41954 [dos]

Possible ATT&CK Techniques 1 AI

T1288
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-3599

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue is an integer overflow in sql/auth/sql_authentication.cc which allows remote attackers to cause a denial of service via a crafted authentication packet.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Oracle MySQL Server 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Oracle MySQL Server是美国甲骨文(Oracle)公司的一套开源的关系数据库管理系统。该数据库系统具有性能高、成本低、可靠性好等特点。 Oracle MySQL中的MySQL Server组件的Server: Pluggable Auth子组件存在安全漏洞。攻击者可利用该漏洞造成服务器拒绝服务(挂起和频繁崩溃),影响数据的可用性。以下版本受到影响:Oracle MySQL 5.6.35及之前的版本,5.7.17及之前的版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2017-3599

# POC Description Source Link Shenlong Link
1 Proof of concept exploit for CVE-2017-3599 https://github.com/SECFORCE/CVE-2017-3599 POC Details
2 A tool to crash MySQL servers with CVE-2017-3599 https://github.com/jptr218/mysql_dos POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-3599

登录查看更多情报信息。

Vendor Advisories for CVE-2017-3599 (5)

Exploits & Public PoCs for CVE-2017-3599 (1)

Security Blog Posts for CVE-2017-3599 (1)

Same Patch Batch · n/a · 2017-04-24 · 69 CVEs total

CVE-2016-6902 lshell 安全漏洞
CVE-2017-5042 Google Chrome Cast 安全漏洞
CVE-2017-5043 Google Chrome for Mac、Windows和Linux 安全漏洞
CVE-2017-5041 Google Chrome 安全漏洞
CVE-2017-5029 Google Chrome Blink libxslt 安全漏洞
CVE-2016-6915 多款NVIDIA产品缓冲区错误漏洞
CVE-2017-3504 Oracle Automatic Service Request 安全漏洞
CVE-2016-6917 Android NVIDIA Video驱动程序提权漏洞
CVE-2016-6916 Android NVIDIA Video驱动程序提权漏洞
CVE-2016-6903 lshell 安全漏洞
CVE-2017-5030 Google Chrome V8 安全漏洞
CVE-2016-5016 多款Pivotal产品安全漏洞
CVE-2011-3438 Apple Safari WebKit 安全漏洞
CVE-2011-3428 Apple QuickTime for Windows 缓冲区错误漏洞
CVE-2010-1776 Apple iPhone和iPod touch iOS Find My iPhone 安全漏洞
CVE-2017-8105 FreeType 2 缓冲区错误漏洞
CVE-2017-8104 MyBB smilie模块路径遍历漏洞
CVE-2017-8103 MyBB Email MyCode组件跨站脚本漏洞
CVE-2017-8102 Serendipity 跨站脚本漏洞
CVE-2017-8101 Serendipity 跨站请求伪造漏洞

Showing top 20 of 69 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-3599

No comments yet


Leave a comment