CVE-2016-0606: Low severity debian linux vulnerability
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption.
Other sources
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.46 and earlier, 5.6.27 and earlier and 5.7.9. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some MySQL Server accessible data.
External References:
http://www.oracle.com/technetwork/topics/security/cpujan2016verbose-2367956.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0606?
The vulnerability CVE-2016-0606 is classified as a medium severity issue affecting multiple versions of Oracle MySQL and MariaDB.
How do I fix CVE-2016-0606?
To address CVE-2016-0606, upgrade to MySQL versions 5.5.47, 5.6.28, or 5.7.10, or MariaDB versions 5.5.47, 10.0.23, or 10.1.10.
What software is affected by CVE-2016-0606?
CVE-2016-0606 affects Oracle MySQL versions 5.5.46 and earlier, 5.6.27 and earlier, 5.7.9 and earlier, and several versions of MariaDB.
Who is at risk from CVE-2016-0606?
Remote authenticated users may exploit CVE-2016-0606 to affect the integrity of systems using the vulnerable versions of MySQL and MariaDB.
What types of vulnerabilities does CVE-2016-0606 involve?
CVE-2016-0606 involves unspecified vectors related to encryption that can impact data integrity.