Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-6664

Опубликовано: 13 дек. 2016
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 6.9
CVSS3: 7

Описание

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

released

10.0.29-0ubuntu0.16.04.1
esm-infra-legacy/trusty

DNE

precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

10.0.29
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

released

10.0.29-0ubuntu0.16.04.1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

not-affected

5.5.52-0ubuntu0.14.04.1
precise

released

5.5.52-0ubuntu0.12.04.1
trusty

released

5.5.52-0ubuntu0.14.04.1
trusty/esm

not-affected

5.5.52-0ubuntu0.14.04.1
upstream

released

5.5.52
vivid

DNE

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [5.6.33-0ubuntu0.14.04.1]]
precise

DNE

trusty

not-affected

5.6.33-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was not-affected [5.6.33-0ubuntu0.14.04.1]
upstream

released

5.6.33
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

DNE

yakkety

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

5.7.15-0ubuntu2
esm-infra-legacy/trusty

DNE

esm-infra/xenial

not-affected

5.7.15-0ubuntu0.16.04.1
precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

5.7.15
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

not-affected

5.7.15-0ubuntu0.16.04.1

Показывать по

EPSS

Процентиль: 97%
0.44687
Средний

6.9 Medium

CVSS2

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 8 лет назад

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.

CVSS3: 7
nvd
больше 8 лет назад

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.

CVSS3: 7
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 7
debian
больше 8 лет назад

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and ...

CVSS3: 7
github
около 3 лет назад

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.

EPSS

Процентиль: 97%
0.44687
Средний

6.9 Medium

CVSS2

7 High

CVSS3

Уязвимость CVE-2016-6664