{"id":"CVE-2016-3471","details":"Unspecified vulnerability in Oracle MySQL 5.5.45 and earlier and 5.6.26 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Option.","modified":"2026-07-08T22:45:39.173280Z","published":"2016-07-21T10:12:25.117Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.0"},{"last_affected":"6.0"},{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux"}]},"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-0534.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-0705.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1480.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-1481.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91787"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91913"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1036362"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2016:1132"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mariadb/server","events":[{"introduced":"5bfe1a3917ee1bddc7f2cde0c88961875148873c"},{"fixed":"b9768521bdeb1a8069c7b871f4536792b65fd79b"},{"introduced":"776555af021e917ce0d6235386b43ae59fdd5161"},{"fixed":"f4421c893b50f05078f14d33c47d21f52f59f8a7"},{"introduced":"c235de12ae3723b96944337bd89ad9cc87f21d8f"},{"fixed":"370a2cbe96e026fdb8966d8e58e7c93f75597cb8"}],"database_specific":{"cpe":"cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.5.0"},{"fixed":"5.5.46"},{"introduced":"10.0.0"},{"fixed":"10.0.22"},{"introduced":"10.1.0"},{"fixed":"10.1.9"}],"source":"CPE_RANGE"}}],"versions":["mariadb-10.1.8","mariadb-10.1.7","mariadb-10.1.6","mariadb-10.1.5","mariadb-10.1.4","mariadb-10.1.3","mariadb-10.1.2","mariadb-10.1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-3471.json","vanir_signatures_modified":"2026-07-08T22:45:39Z","vanir_signatures":[{"target":{"file":"extra/yassl/src/yassl_imp.cpp","function":"CertificateVerify::Build"},"deprecated":false,"digest":{"function_hash":"272044820098228092970937818851523802945","length":1279},"id":"CVE-2016-3471-5c63033b","signature_type":"Function","signature_version":"v1","source":"https://github.com/mariadb/server/commit/b9768521bdeb1a8069c7b871f4536792b65fd79b"},{"deprecated":false,"digest":{"function_hash":"315503665402952802675592496886709669772","length":4731},"id":"CVE-2016-3471-7005bf51","signature_type":"Function","signature_version":"v1","source":"https://github.com/mariadb/server/commit/b9768521bdeb1a8069c7b871f4536792b65fd79b","target":{"function":"SetErrorString","file":"extra/yassl/src/yassl_error.cpp"}},{"digest":{"function_hash":"46975870005828366040638209346810365877","length":2559},"id":"CVE-2016-3471-8c3171f1","signature_type":"Function","signature_version":"v1","source":"https://github.com/mariadb/server/commit/b9768521bdeb1a8069c7b871f4536792b65fd79b","target":{"file":"extra/yassl/src/yassl_imp.cpp","function":"DH_Server::build"},"deprecated":false},{"id":"CVE-2016-3471-8d5793e4","signature_type":"Line","signature_version":"v1","source":"https://github.com/mariadb/server/commit/b9768521bdeb1a8069c7b871f4536792b65fd79b","target":{"file":"extra/yassl/src/yassl_error.cpp"},"deprecated":false,"digest":{"line_hashes":["57248392826115285220715661389409750131","119661056949224539051154886786283811515","101696571178136960950076477160822307085"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/mariadb/server/commit/b9768521bdeb1a8069c7b871f4536792b65fd79b","target":{"file":"extra/yassl/src/yassl_imp.cpp"},"deprecated":false,"digest":{"line_hashes":["318191172539277246755459617926955744505","254541478843544755662381547845904652300","54611158850969751301851086590952628930","302163634400636825149017150007684831665","189998908723996230938131694619656807943","116866421171719334797154527726827554745","63002157905645375881709121950844844710","213730524434689387980355047141216967259","171851186081481727127885226401230028656","111686806875080769917645340067285185153"],"threshold":0.9},"id":"CVE-2016-3471-bda7a2dd","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/mariadb/server/commit/b9768521bdeb1a8069c7b871f4536792b65fd79b","target":{"file":"extra/yassl/include/yassl_error.hpp"},"deprecated":false,"digest":{"line_hashes":["53228238731089417596214118720962938977","277402405450698143280666152936637809078","144031700655018854448410967691007543222","67642837746220755452538215699521074013"],"threshold":0.9},"id":"CVE-2016-3471-cbe2a036","signature_type":"Line"},{"source":"https://github.com/mariadb/server/commit/b9768521bdeb1a8069c7b871f4536792b65fd79b","target":{"file":"extra/yassl/src/handshake.cpp","function":"sendCertificateVerify"},"deprecated":false,"digest":{"function_hash":"65883879829300206530716652549419963265","length":511},"id":"CVE-2016-3471-e6670ae9","signature_type":"Function","signature_version":"v1"},{"target":{"file":"extra/yassl/src/handshake.cpp"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["206466407836171049544989872457880780103","300898926962521654039968805530655777728","53859862795470716343051009615782488068","96932451662644561594274820598624521910"]},"id":"CVE-2016-3471-f20a4f0f","signature_type":"Line","signature_version":"v1","source":"https://github.com/mariadb/server/commit/b9768521bdeb1a8069c7b871f4536792b65fd79b"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/mysql/mysql-server","events":[{"introduced":"54df0057e18d8c82c23fbd4e0bf5b5dc2e762955"},{"last_affected":"830bcff0edd3dd031932e60c7a70fe92a63fc404"},{"introduced":"0"},{"last_affected":"9c6193fad44e276fdadc4ea74c87c682daf2e947"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.5.0"},{"last_affected":"5.5.45"},{"introduced":"5.6.0"},{"last_affected":"5.6.26"}]}}],"versions":["mysql-5.6.26","mysql-5.5.45","mysql-5.5.44","mysql-5.5.27","mysql-5.5.25","mysql-5.5.23","mysql-5.5.19","mysql-5.5.15","mysql-5.1.4","mysql-4.0.4","mysql-4.0.2","mysql-3.23.36","mysql-3.23.33","mysql-3.23.32","mysql-3.23.31","mysql-3.23.30-gamma","mysql-3.23.28-gamma","mysql-3.23.22-beta"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-3471.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}