10

CVE-2016-6662

Exploit
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleMysql Version >= 5.5.0 <= 5.5.52
OracleMysql Version >= 5.6.0 <= 5.6.33
OracleMysql Version >= 5.7.0 <= 5.7.15
PerconaPercona Server Version >= 5.5 < 5.5.51-38.1
PerconaPercona Server Version >= 5.6 < 5.6.32-78.0
PerconaPercona Server Version >= 5.7 < 5.7.14-7
MariadbMariadb Version >= 5.5.20 < 5.5.51
MariadbMariadb Version >= 10.0.0 < 10.0.27
MariadbMariadb Version >= 10.1.0 < 10.1.17
DebianDebian Linux Version8.0
RedhatOpenstack Version5.0
RedhatOpenstack Version6.0
RedhatOpenstack Version7.0
RedhatOpenstack Version8
RedhatOpenstack Version9
RedhatEnterprise Linux Version7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 89.58% 0.995
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://seclists.org/fulldisclosure/2016/Sep/23
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/92912
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1036769
Third Party Advisory
VDB Entry
https://jira.mariadb.org/browse/MDEV-10465
Vendor Advisory
Issue Tracking
https://www.exploit-db.com/exploits/40360/
Third Party Advisory
Exploit
VDB Entry