Описание
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.
A flaw was found in the way the mysqld_safe script handled creation of error log file. The mysql operating system user could use this flaw to escalate their privileges to root.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | mysql55-mysql | Will not fix | ||
Red Hat Enterprise Linux 6 | mysql | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | mariadb-galera | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | mariadb-galera | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | mariadb-galera | Will not fix | ||
Red Hat OpenStack Platform 10 (Newton) | mariadb-galera | Will not fix | ||
Red Hat OpenStack Platform 11 (Ocata) | mariadb-galera | Will not fix | ||
Red Hat OpenStack Platform 12 (Pike) | mariadb-galera | Will not fix | ||
Red Hat OpenStack Platform 8 (Liberty) | mariadb-galera | Will not fix | ||
Red Hat OpenStack Platform 9 (Mitaka) | mariadb-galera | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
6.8 Medium
CVSS2
Связанные уязвимости
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and ...
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.
EPSS
7.8 High
CVSS3
6.8 Medium
CVSS2