PT-2016-7029 · Mariadb+7 · Mariadb+8

Dawid Golunski

·

Published

2016-10-18

·

Updated

2024-06-15

·

CVE-2016-6664

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.5.51 and earlier, 5.6.32 and earlier, 5.7.14 and earlier MariaDB (affected versions not specified) Percona Server versions 5.5.51-38.2 and earlier, 5.6.32-78.1 and earlier, 5.7.14-8 and earlier Percona XtraDB Cluster versions 5.5.41-37.0 and earlier, 5.6.32-25.17 and earlier, 5.7.14-26.17 and earlier
Description The issue allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files when using file-based logging. It can also be exploited by a high-privileged attacker with network access via multiple protocols to compromise the MySQL Server, resulting in unauthorized ability to cause a hang or frequently repeatable crash of the MySQL Server.
Recommendations For Oracle MySQL versions 5.5.51 and earlier, 5.6.32 and earlier, 5.7.14 and earlier, update to a version later than the affected ones. For MariaDB, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Percona Server versions 5.5.51-38.2 and earlier, 5.6.32-78.1 and earlier, 5.7.14-8 and earlier, update to a version later than the affected ones. For Percona XtraDB Cluster versions 5.5.41-37.0 and earlier, 5.6.32-25.17 and earlier, 5.7.14-26.17 and earlier, update to a version later than the affected ones. As a temporary workaround, consider disabling file-based logging until a patch is available. Restrict access to the mysql account to minimize the risk of exploitation.

Exploit

DoS

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2238
ALT-PU-2017-1061
CESA-2017_2192
CVE-2016-6664
DSA-3770-1
ELSA-2017-2192
MGASA-2017-0054
OPENSUSE-SU-2017_0486-1
OPENSUSE-SU-2024:11038-1
RHSA-2016:2130
RHSA-2016:2749
RHSA-2017:2192
RHSA-2017_2192
RHSA-2018:0279
RHSA-2018:0574
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1
SUSE-SU-2017:0411-1
SUSE-SU-2017:0412-1
SUSE-SU-2017_0408-1
SUSE-SU-2017_0411-1
SUSE-SU-2017_0412-1

Affected Products

Alt Linux
Centos
Mariadb
Mariadb Server
Mysql Server
Percona Server
Percona Xtradb Cluster
Red Hat
Suse