Name | CVE-2017-3302 |
Description | Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-819-1, DLA-916-1, DSA-3809-1, DSA-3834-1 |
Debian Bugs | 854713, 860544 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
mariadb-10.0 | source | jessie | 10.0.30-0+deb8u1 | DSA-3809-1 | ||
mariadb-10.0 | source | (unstable) | (unfixed) | |||
mariadb-10.1 | source | (unstable) | 10.1.23-1 | |||
mysql-5.5 | source | wheezy | 5.5.55-0+deb7u1 | DLA-916-1 | ||
mysql-5.5 | source | jessie | 5.5.55-0+deb8u1 | DSA-3834-1 | ||
mysql-5.5 | source | (unstable) | (unfixed) | 854713, 860544 | ||
mysql-5.6 | source | (unstable) | (not affected) | |||
mysql-5.7 | source | (unstable) | (not affected) |
- mysql-5.7 <not-affected> (Fixed before initial release in Debian)
- mysql-5.6 <not-affected> (Fixed before initial release in Debian)
Fixed by: https://github.com/mysql/mysql-server/commit/4797ea0b772d5f4c5889bc552424132806f46e93
Fixed in Oracle MySQL 5.6.21, 5.7.5
https://bugs.mysql.com/bug.php?id=70429
https://bugs.mysql.com/bug.php?id=63363
https://www.openwall.com/lists/oss-security/2017/01/28/1