First published: Tue Sep 20 2016(Updated: )
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle MySQL | >=5.5.0<=5.5.52 | |
Oracle MySQL | >=5.6.0<=5.6.33 | |
Oracle MySQL | >=5.7.0<=5.7.15 | |
Percona Percona Server | >=5.5<5.5.51-38.1 | |
Percona Percona Server | >=5.6<5.6.32-78.0 | |
Percona Percona Server | >=5.7<5.7.14-7 | |
Mariadb Mariadb | >=5.5.20<5.5.51 | |
Mariadb Mariadb | >=10.0.0<10.0.27 | |
Mariadb Mariadb | >=10.1.0<10.1.17 | |
Debian Debian Linux | =8.0 | |
Redhat Openstack | =5.0 | |
Redhat Openstack | =6.0 | |
Redhat Openstack | =7.0 | |
Redhat Openstack | =8 | |
Redhat Openstack | =9 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server Aus | =7.3 | |
Redhat Enterprise Linux Server Aus | =7.4 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Eus | =7.3 | |
Redhat Enterprise Linux Server Eus | =7.4 | |
Redhat Enterprise Linux Server Eus | =7.5 | |
Redhat Enterprise Linux Server Eus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.3 | |
Redhat Enterprise Linux Server Tus | =7.6 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.