Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5483

Опубликовано: 09 мар. 2017
Источник: redhat
CVSS3: 6.4

Описание

It was discovered that the mysql and mysqldump tools did not correctly handle database and table names containing newline characters. A database user with privileges to create databases or tables could cause the mysql command to execute arbitrary shell or SQL commands while restoring database backup created using the mysqldump tool.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5mysql55-mysqlWill not fix
Red Hat Enterprise Linux 6mysqlWill not fix
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)mariadb-galeraWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)mariadb-galeraWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)mariadb-galeraWill not fix
Red Hat Mobile Application Platform 4rhmap-mysql-dockerAffected
Red Hat OpenStack Platform 10 (Newton)mariadb-galeraWill not fix
Red Hat OpenStack Platform 11 (Ocata)mariadb-galeraWill not fix
Red Hat OpenStack Platform 12 (Pike)mariadb-galeraWill not fix
Red Hat OpenStack Platform 8 (Liberty)mariadb-galeraWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1433010mysql: Incorrect input validation allowing code execution via mysqldump

6.4 Medium

CVSS3

Связанные уязвимости

ubuntu
около 8 лет назад

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-3600. Reason: This candidate is a reservation duplicate of CVE-2017-3600. Notes: All CVE users should reference CVE-2017-3600 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

nvd
около 8 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-3600. Reason: This candidate is a reservation duplicate of CVE-2017-3600. Notes: All CVE users should reference CVE-2017-3600 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

suse-cvrf
около 8 лет назад

Security update for mysql

suse-cvrf
около 8 лет назад

Security update for mysql-community-server

oracle-oval
почти 8 лет назад

ELSA-2017-2192: mariadb security and bug fix update (MODERATE)

6.4 Medium

CVSS3