← Vulnerability feed

Vulnerability record · CVE-2017-3599 · published 24 April 2017

CVE-2017-3599: MySQL Server Pluggable Auth integer overflow allows pre-auth remote DoS

Oracle · Mysql

CVE-2017-3599 is an integer overflow in MySQL Server's Pluggable Auth subcomponent, affecting versions 5.6.35 and earlier and 5.7.17 and earlier. A remote, unauthenticated attacker can send a crafted authentication packet that causes a hang or repeatable crash of the server, making it a complete denial-of-service condition. Oracle has not confirmed the third-party claim that the root cause is an integer overflow in sql/auth/sql_authentication.cc.

7.5 CVSS 3.0 High EPSS 90% · top 0.2% CWE-190 · Integer overflow
7.5CVSS 3.0 base score, v2 7.8
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue is an integer overflow in sql/auth/sql_authentication.cc which allows remote attackers to cause a denial of service via a crafted authentication packet.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote network access with low attack complexity and a complete availability impact, backed by public exploit code and very high EPSS, though it is not in KEV and causes only denial of service.

What it is

CVE-2017-3599 is an integer overflow in MySQL Server's Pluggable Auth subcomponent, affecting versions 5.6.35 and earlier and 5.7.17 and earlier. A remote, unauthenticated attacker can send a crafted authentication packet that causes a hang or repeatable crash of the server, making it a complete denial-of-service condition. Oracle has not confirmed the third-party claim that the root cause is an integer overflow in sql/auth/sql_authentication.cc.

Impact

An attacker can crash or hang the MySQL server without any credentials, disrupting all applications and users that depend on that database instance. There is no confidentiality or integrity impact; only availability is affected.

Attack surface

The flaw is reachable over the network via multiple protocols on the MySQL listener, with no authentication and no user interaction required (CVSS AV:N/AC:L/PR:N/UI:N). Any host that can reach the MySQL port can attempt it.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.899 probability, 99.8th percentile) and public exploit references exist, including an Exploit-DB entry and a vendor-independent pre-auth remote DoS writeup. This indicates mature, widely available exploit code.

What to do

  • Apply the April 2017 Oracle Critical Patch Update for MySQL Server, or upgrade to a release later than 5.6.35 / 5.7.17; apply the referenced Red Hat errata (RHSA-2017:2787, RHSA-2017:2886) where applicable.
  • Restrict network access to MySQL ports (default 3306) with firewall rules and bind-address so only trusted application hosts can connect.
  • Do not expose MySQL directly to untrusted networks or the internet; place it behind a proxy or VPN.
  • Monitor and rate-limit authentication attempts at the network or proxy layer to reduce the ability to deliver crafted auth packets at volume.
  • If patching cannot be done immediately, isolate affected instances and prepare failover capacity to absorb repeated crashes.

Detection

  • Alert on MySQL server process crashes, restarts, or unexpected shutdowns, correlating them with inbound connections to the MySQL port.
  • Monitor for repeated or malformed authentication packets and abnormal connection churn from single source IPs.
  • Review MySQL error logs for authentication-related errors or aborts preceding a service restart.
  • Track MySQL version inventory to identify instances still running 5.6.35 or earlier and 5.7.17 or earlier.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-3599 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2750Oracle mysql vulnerabilityUnspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this …EPSS 3.6%10.0CVE-2004-0836Oracle mysql memory buffer overflow vulnerabilityBuffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of…EPSS 9.8%9.8CVE-2020-11656Sqlite use after free vulnerabilityIn SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELEC…EPSS 7.6%9.8CVE-2019-14540Fasterxml jackson-databind deserialization of untrusted data vulnerabilityA Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.EPSS 11%9.8CVE-2016-9841Zlib vulnerabilityinffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.EPSS 7.6%9.8CVE-2016-9843Zlib vulnerabilityThe crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian C…EPSS 5.8%9.8CVE-2016-6662MySQL, MariaDB and Percona Server local privilege escalation via general_log_fileMySQL, MariaDB and Percona Server allow a local user to set general_log_file to a my.cnf configuration path, creating arbitrary configuration files a…EPSS 68%analysed9.8CVE-2016-0639Redhat enterprise linux vulnerabilityUnspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2017-3599), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.