Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7221

Опубликовано: 04 фев. 2020
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

A privilege escalation vulnerability was found in MariaDB, in the way it handled a setuid program during the installation process. A local MySQL user could abuse this flaw to escalate their privileges on the system, by gaining root privileges once the bash script mysql_install_db.sh is executed.

Отчет

This flaw did not affect the versions of MariaDB as shipped with Red Hat Enterprise Linux 7, and 8 as they did not include the vulnerable code, which was introduced in a newer version of the package. The same is true for the versions of MariaDB as shipped with Red Hat Software Collections 3.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mariadbNot affected
Red Hat Enterprise Linux 8mariadbNot affected
Red Hat OpenStack Platform 13 (Queens)mariadbNot affected
Red Hat Software Collectionsrh-mariadb102Not affected
Red Hat Software Collectionsrh-mariadb103Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-267
https://bugzilla.redhat.com/show_bug.cgi?id=1802786mariadb: mysql_install_db allows privilege escalation due to unsafe chown and chmod operations

EPSS

Процентиль: 50%
0.00269
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
nvd
больше 5 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
debian
больше 5 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege es ...

github
около 3 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
fstec
больше 5 лет назад

Уязвимость функции mysql_install_db системы управления базами данных MariaDB, связанная с некорректным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 50%
0.00269
Низкий

7.8 High

CVSS3