PT-2016-7029 · Mariadb+7 · Mariadb+8

Dawid Golunski

·

Publicado

2016-10-18

·

Atualizado

2024-06-15

·

CVE-2016-6664

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.5.51 and earlier, 5.6.32 and earlier, 5.7.14 and earlier MariaDB (affected versions not specified) Percona Server versions 5.5.51-38.2 and earlier, 5.6.32-78.1 and earlier, 5.7.14-8 and earlier Percona XtraDB Cluster versions 5.5.41-37.0 and earlier, 5.6.32-25.17 and earlier, 5.7.14-26.17 and earlier
Description The issue allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files when using file-based logging. It can also be exploited by a high-privileged attacker with network access via multiple protocols to compromise the MySQL Server, resulting in unauthorized ability to cause a hang or frequently repeatable crash of the MySQL Server.
Recommendations For Oracle MySQL versions 5.5.51 and earlier, 5.6.32 and earlier, 5.7.14 and earlier, update to a version later than the affected ones. For MariaDB, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Percona Server versions 5.5.51-38.2 and earlier, 5.6.32-78.1 and earlier, 5.7.14-8 and earlier, update to a version later than the affected ones. For Percona XtraDB Cluster versions 5.5.41-37.0 and earlier, 5.6.32-25.17 and earlier, 5.7.14-26.17 and earlier, update to a version later than the affected ones. As a temporary workaround, consider disabling file-based logging until a patch is available. Restrict access to the mysql account to minimize the risk of exploitation.

Exploit

DoS

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2238
ALT-PU-2017-1061
CESA-2017_2192
CVE-2016-6664
DSA-3770-1
ELSA-2017-2192
MGASA-2017-0054
OPENSUSE-SU-2017_0486-1
OPENSUSE-SU-2024:11038-1
RHSA-2016:2130
RHSA-2016:2749
RHSA-2017:2192
RHSA-2017_2192
RHSA-2018:0279
RHSA-2018:0574
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1
SUSE-SU-2017:0411-1
SUSE-SU-2017:0412-1
SUSE-SU-2017_0408-1
SUSE-SU-2017_0411-1
SUSE-SU-2017_0412-1

Produtos afetados

Alt Linux
Centos
Mariadb
Mariadb Server
Mysql Server
Percona Server
Percona Xtradb Cluster
Red Hat
Suse