Описание
Insecure $HOME in MariaDB rpm packages
Impact
MariaDB rpm packages created a dedicated mysql user to run mariadbd as, and this user had its home dir set to the datadir. Such a configuration allowed a malicious user with FILE privilege to create various dot-files in $HOME. For example, a .bash_profile would be executed when someone does su - mysql -s /bin/bash.
MariaDB deb packages are not vulnerable, as the home there is set to /nonexistent.
Patches
Fixed in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2.
Workarounds
Change the home for mysql user to something mariadbd cannot write to. For example usermod -d / mysql or usermod -d /nonexistent mysql.
Пакеты
mariadb
>=10.6.1, <=10.6.27
10.6.28
mariadb
>=10.11.1, <=10.11.18
10.11.19
mariadb
>=11.4.1, <=11.4.12
11.4.13
mariadb
>=11.8.1, <=11.8.8
11.8.9
mariadb
>=12.3.1, <=12.3.2
12.3.3
mariadb
13.0.1
13.0.2
8.4 High
CVSS3
Дефекты
8.4 High
CVSS3