First published: Fri Apr 08 2016(Updated: )
The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and before 10.0.22-3.1 in SUSE Linux Enterprise (SLE) 12.1 and openSUSE Leap 42.1 allows local users to discover database credentials by listing a process and its arguments.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =42.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Desktop | =12-sp1 | |
SUSE Linux Enterprise Server | =12-sp1 | |
SUSE Linux Enterprise Software Development Kit | =12-sp1 | |
SUSE Linux Workstation Extension | =12-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5969 is classified as a medium severity vulnerability.
To fix CVE-2015-5969, upgrade to mysql-community-server version 5.6.28-2.17.1 or later for openSUSE 13.2 and version 10.0.22-2.21.2 or later for mariadb.
CVE-2015-5969 affects mysql-community-server before 5.6.28-2.17.1 and mariadb before 10.0.22-2.21.2 on specified openSUSE and SUSE Linux Enterprise versions.
CVE-2015-5969 can allow unauthorized access to MySQL services on affected systems.
Yes, CVE-2015-5969 primarily affects openSUSE and SUSE Linux Enterprise systems.