CVE-2017-3599 is an integer overflow/underflow vulnerability in Oracle MySQL Server's Server: Pluggable Authentication connection-handshake parsing, associated with handling performed by get_56_lenc_string(). A crafted authentication or connection handshake packet can cause an invalid length calculation leading to a buffer-overflow condition or over-read and terminate or hang the mysqld daemon. Oracle MySQL 5.6.35 and earlier and 5.7.17 and earlier are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Python script, 'cve-2017-3599_poc.py', which is a proof-of-concept exploit for CVE-2017-3599, a pre-authentication remote denial of service vulnerability in Oracle MySQL. The script constructs a specially crafted MySQL login request packet with a malformed authentication field and sends it to a target MySQL server over TCP (default port 3306). If the target is vulnerable, the server will crash upon receiving the packet, resulting in a denial of service. The script requires the user to specify the target host (and optionally the port) as command-line arguments. The exploit demonstrates the vulnerability but does not provide post-exploitation capabilities or a customizable payload. The code is straightforward, with clear comments explaining the packet structure and the conditions required to trigger the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unauthenticated remote denial-of-service vulnerability in MySQL handshake parsing; an attacker with MySQL-port access could crash mysqld.
Unauthenticated remote denial of service through an integer underflow/overflow in MySQL handshake parsing.
A pre-authentication remote denial-of-service vulnerability in Oracle MySQL Server's Pluggable Authentication component. An unauthenticated network attacker can send a crafted authentication message during the connection handshake, triggering an integer underflow that may lead to a buffer over-read and causing mysqld to hang or repeatedly crash.
An important, network-reachable pre-authentication denial-of-service vulnerability in MySQL connection-handshake parsing. An integer overflow/underflow can result in a buffer overflow and allow an unauthenticated attacker able to reach the MySQL service port to crash mysqld.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.