CVE Database
/

CVE-2016-6662

Back to search

CVE-2016-6662

Published: Sep 20, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2016:2749
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0184
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2131
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2060
vendor-advisory
x_refsource_REDHAT
92912
vdb-entry
x_refsource_BID
GLSA-201701-01
vendor-advisory
x_refsource_GENTOO
DSA-3666
vendor-advisory
x_refsource_DEBIAN
RHSA-2016:2130
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2077
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2927
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2059
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2062
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2595
vendor-advisory
x_refsource_REDHAT
1036769
vdb-entry
x_refsource_SECTRACK
RHSA-2016:2061
vendor-advisory
x_refsource_REDHAT
40360
exploit
x_refsource_EXPLOIT-DB
RHSA-2016:2928
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2058
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now