PT-2016-7027 · Oracle+8 · Mysql Server+8

Dawid Golunski

·

Publicado

2016-08-10

·

Atualizado

2025-10-17

·

CVE-2016-6662

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.5.52 and earlier, 5.6.33 and earlier, 5.7.15 and earlier MariaDB versions prior to 5.5.51, 10.0.x prior to 10.0.27, and 10.1.x prior to 10.1.17 Percona Server versions prior to 5.5.51-38.1, 5.6.x prior to 5.6.32-78.0, and 5.7.x prior to 5.7.14-7
Description The issue allows local users to create arbitrary configurations and bypass certain protection mechanisms by setting general log file to a my.cnf configuration. This can be leveraged to execute arbitrary code with root privileges by setting malloc lib. The vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Server.
Recommendations For Oracle MySQL versions 5.5.52 and earlier, 5.6.33 and earlier, 5.7.15 and earlier, consider disabling the general log file setting to prevent exploitation until a patch is available. For MariaDB versions prior to 5.5.51, 10.0.x prior to 10.0.27, and 10.1.x prior to 10.1.17, restrict access to the my.cnf configuration file to minimize the risk of exploitation. For Percona Server versions prior to 5.5.51-38.1, 5.6.x prior to 5.6.32-78.0, and 5.7.x prior to 5.7.14-7, avoid using the malloc lib setting in the my.cnf configuration until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
ALT-PU-2016-1934
ALT-PU-2016-2238
CESA-2016_2595
CESA-2017_0184
CVE-2016-6662
DLA-624-1
DSA-3666-1
ELSA-2016-2595
ELSA-2017-0184
OPENSUSE-SU-2016_2448-1
OPENSUSE-SU-2016_2746-1
OPENSUSE-SU-2016_2769-1
OPENSUSE-SU-2016_2788-1
OPENSUSE-SU-2024:10200-1
RHSA-2016:2058
RHSA-2016:2059
RHSA-2016:2060
RHSA-2016:2061
RHSA-2016:2062
RHSA-2016:2077
RHSA-2016:2130
RHSA-2016:2131
RHSA-2016:2595
RHSA-2016:2749
RHSA-2016:2927
RHSA-2016:2928
RHSA-2016_2595
RHSA-2017:0184
RHSA-2017_0184
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1
SUSE-SU-2016:2343-1
SUSE-SU-2016:2395-1
SUSE-SU-2016:2404-1
SUSE-SU-2016:2780-1
SUSE-SU-2016_2343-1
SUSE-SU-2016_2395-1
SUSE-SU-2016_2404-1
SUSE-SU-2016_2780-1
USN-3078-1

Produtos afetados

Alt Linux
Centos
Mariadb
Mariadb Server
Mysql Server
Percona Server
Red Hat
Suse
Ubuntu