QID 375989

Date Published: 2021-10-28

QID 375989: Oracle MySQL Connectors 8.0.x Denial of Service (DoS) Vulnerability (cpuoct2021)

Oracle MySQL Connector/ODBC is a standardized database driver for Windows, Linux, Mac OS X, and Unix platforms.

OpenSSL is used by Oracle MySQL Connector. Oracle MySQL Connector has addressed the applicable CVEs.
CVE-2021-2471: Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors..

Affected Version:
MySQL Connector/ODBC 8.0.x prior to 8.0.27

QID Detection Logic (Authenticated):
This QID checks for the file version of MySQL Connector/ODBC

Successful exploitation of this vulnerability may allow a privileged attacker to hang or frequently repeatable crash (complete DOS) of MySQL Connectors.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as High - 7.9 severity.
  • Solution
    MySQL has released Oracle MySQL Connector 8.0.27 to mitigate these vulnerabilities. Refer to advisory MySQL Connector 8.0.x

    Vendor References

    CVEs related to QID 375989

    Software Advisories
    Advisory ID Software Component Link
    MySQL Connector 8.0.x URL Logo www.oracle.com/security-alerts/cpuoct2021.html#AppendixMSQL