vulnerability

Oracle Linux: CVE-2016-6662: ELSA-2016-2595: mariadb security and bug fix update (IMPORTANT) (Multiple Advisories)

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
2016-09-12
Added
2016-11-09
Modified
2025-01-07

Description

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.
It was discovered that the MySQL logging functionality allowed writing to MySQL configuration files. An administrative database user, or a database user with FILE privileges, could possibly use this flaw to run arbitrary commands with root privileges on the system running the database server.

Solution(s)

oracle-linux-upgrade-mariadboracle-linux-upgrade-mariadb-benchoracle-linux-upgrade-mariadb-develoracle-linux-upgrade-mariadb-embeddedoracle-linux-upgrade-mariadb-embedded-develoracle-linux-upgrade-mariadb-libsoracle-linux-upgrade-mariadb-serveroracle-linux-upgrade-mariadb-testoracle-linux-upgrade-mysqloracle-linux-upgrade-mysql-benchoracle-linux-upgrade-mysql-develoracle-linux-upgrade-mysql-embeddedoracle-linux-upgrade-mysql-embedded-develoracle-linux-upgrade-mysql-libsoracle-linux-upgrade-mysql-serveroracle-linux-upgrade-mysql-test
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.