Vulnerability Name:

CVE-2017-3635 (CCN-129001)

Assigned:2016-12-06
Published:2017-07-18
Updated:2019-10-03
Summary:Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/C). Supported versions that are affected are 6.1.10 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors.
Note: The documentation has also been updated for the correct way to use mysql_stmt_close(). Please see: https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-execute.html, https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-fetch.html, https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-close.html, https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-error.html, https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-errno.html, and https://dev.mysql.com/doc/refman/5.7/en/mysql-stmt-sqlstate.html. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.9 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2017-3635

Source: DEBIAN
Type: Third Party Advisory
DSA-3922

Source: CCN
Type: IBM Security Bulletin 2010702 (Security Guardium)
IBM Security Guardium Database Activity Monitor is affected by vulnerabilities in Oracle MySQL (Multiple CVEs)

Source: CCN
Type: Oracle CPUJul2017
Oracle Critical Patch Update Advisory - July 2017

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html

Source: BID
Type: Third Party Advisory, VDB Entry
99730

Source: CCN
Type: BID-99730
Oracle MySQL Connectors/MySQL Server CVE-2017-3635 Remote Security Vulnerability

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1038928

Source: XF
Type: UNKNOWN
oracle-cpujul2017-cve20173635(129001)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:mysql:*:*:*:*:*:*:*:* (Version >= 5.5.0 and <= 5.5.56)
  • OR cpe:/a:oracle:mysql:*:*:*:*:*:*:*:* (Version >= 5.6.0 and <= 5.6.36)
  • OR cpe:/a:oracle:mysql:*:*:*:*:*:*:*:* (Version >= 5.7.0 and <= 5.7.18)
  • OR cpe:/a:oracle:mysql_connector/c:*:*:*:*:*:*:*:* (Version <= 6.1.10)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:mysql:5.7.18:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.6.36:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.5.56:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql_connectors:6.1.10:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:security_guardium:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:9.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20173635
    V
    CVE-2017-3635
    2022-05-20
    oval:org.opensuse.security:def:34673
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:34604
    P
    Security update for speex (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:31300
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:30264
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:31290
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-10-18
    oval:org.opensuse.security:def:34565
    P
    Security update for iproute2 (Moderate)
    2021-10-18
    oval:org.opensuse.security:def:30121
    P
    Security update for openexr (Important)
    2021-09-02
    oval:org.opensuse.security:def:31262
    P
    Security update for openexr (Important)
    2021-09-02
    oval:org.opensuse.security:def:32176
    P
    Security update for aspell (Important)
    2021-08-25
    oval:org.opensuse.security:def:34516
    P
    Security update for openssl-1_0_0 (Important)
    2021-08-24
    oval:org.opensuse.security:def:32137
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:34458
    P
    Security update for apache2-mod_auth_openidc (Important)
    2021-06-08
    oval:org.opensuse.security:def:36228
    P
    libvorbis-1.2.0-79.20.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36186
    P
    libfreebl3-3.17.3-0.8.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:33921
    P
    Security update for the Linux Kernel (Important)
    2021-06-08
    oval:org.opensuse.security:def:30178
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP2) (Important)
    2021-04-12
    oval:org.opensuse.security:def:30033
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:31346
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:34629
    P
    Security update for bind (Important)
    2021-02-18
    oval:org.opensuse.security:def:35548
    P
    freetype2-2.3.7-25.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:29828
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:28285
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34691
    P
    Security update for xorg-x11-libX11
    2020-12-01
    oval:org.opensuse.security:def:35023
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30580
    P
    Security update for libfreebl3
    2020-12-01
    oval:org.opensuse.security:def:30899
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:35438
    P
    Security update for openvpn-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26912
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33827
    P
    Security update for gnome-session (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27413
    P
    gmime-2_4-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29816
    P
    Security update for jasper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34211
    P
    Security update for php5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27612
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:34787
    P
    Security update for OpenEXR (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30522
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:30693
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:35330
    P
    Security update for microcode_ctl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26837
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31134
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27178
    P
    libcgroup1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31455
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34057
    P
    Security update for libvorbis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27554
    P
    rubygem-actionpack-3_2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29901
    P
    Security update for krb5
    2020-12-01
    oval:org.opensuse.security:def:34692
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30418
    P
    Security update for xorg-x11-libXfixes (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35311
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:30681
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35080
    P
    Security update for java-1_7_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30624
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:30990
    P
    Security update for jakarta-commons-fileupload
    2020-12-01
    oval:org.opensuse.security:def:35477
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27040
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31395
    P
    Security update for perl
    2020-12-01
    oval:org.opensuse.security:def:33838
    P
    Security update for gpgme
    2020-12-01
    oval:org.opensuse.security:def:27466
    P
    libnetpbm-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29817
    P
    Security update for jasper (Low)
    2020-12-01
    oval:org.opensuse.security:def:34300
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28250
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34923
    P
    Security update for exempi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30561
    P
    Security update for libotr
    2020-12-01
    oval:org.opensuse.security:def:30767
    P
    Security update for aspell (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35389
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26848
    P
    yast2-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33826
    P
    Security update for glibc
    2020-12-01
    oval:org.opensuse.security:def:27262
    P
    pcsc-lite on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31499
    P
    Security update for python-paramiko (Important)
    2020-12-01
    oval:org.opensuse.security:def:34154
    P
    Security update for openssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:27568
    P
    struts on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34703
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:30473
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:35352
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30682
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35170
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26836
    P
    unzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31047
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:35504
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27121
    P
    fastjar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31434
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27515
    P
    mercurial on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201736350000000
    V
    CVE-2017-3635 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-08-08
    oval:com.ubuntu.artful:def:20173635000
    V
    CVE-2017-3635 on Ubuntu 17.10 (artful) - medium.
    2017-08-08
    oval:com.ubuntu.xenial:def:20173635000
    V
    CVE-2017-3635 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-08-08
    oval:com.ubuntu.xenial:def:201736350000000
    V
    CVE-2017-3635 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-08-08
    oval:com.ubuntu.bionic:def:20173635000
    V
    CVE-2017-3635 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-08-08
    oval:com.ubuntu.disco:def:201736350000000
    V
    CVE-2017-3635 on Ubuntu 19.04 (disco) - medium.
    2017-08-08
    oval:com.ubuntu.cosmic:def:20173635000
    V
    CVE-2017-3635 on Ubuntu 18.10 (cosmic) - medium.
    2017-08-08
    oval:com.ubuntu.cosmic:def:201736350000000
    V
    CVE-2017-3635 on Ubuntu 18.10 (cosmic) - medium.
    2017-08-08
    oval:com.ubuntu.trusty:def:20173635000
    V
    CVE-2017-3635 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-08-08
    BACK
    oracle mysql *
    oracle mysql *
    oracle mysql *
    oracle mysql connector/c *
    debian debian linux 8.0
    oracle mysql 5.7.18
    oracle mysql 5.6.36
    oracle mysql 5.5.56
    oracle mysql connectors 6.1.10
    ibm security guardium 9.0
    ibm security guardium 9.1
    ibm security guardium 9.5