7
CVE-2016-6664
- EPSS 47.35%
- Veröffentlicht 13.12.2016 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Percona ≫ Percona Server Version >= 5.5 < 5.5.51-38.2
Percona ≫ Percona Server Version >= 5.6 < 5.6.32-78.1
Percona ≫ Percona Server Version >= 5.7 < 5.7.14-8
Percona ≫ Xtradb Cluster Version >= 5.5 < 5.5.41-37.0
Percona ≫ Xtradb Cluster Version >= 5.6 < 5.6.32-25.17
Percona ≫ Xtradb Cluster Version >= 5.7 < 5.7.14-26.17
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 47.35% | 0.976 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.