CVE-2016-6664

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
oraclemysql
5.5.0 ≤
𝑥
≤ 5.5.51
oraclemysql
5.6.0 ≤
𝑥
≤ 5.6.32
oraclemysql
5.7.0 ≤
𝑥
≤ 5.7.14
mariadbmariadb
5.5.0 ≤
𝑥
< 5.5.54
mariadbmariadb
10.0.0 ≤
𝑥
< 10.0.29
mariadbmariadb
10.1.0 ≤
𝑥
< 10.1.21
perconapercona_server
5.5 ≤
𝑥
< 5.5.51-38.2
perconapercona_server
5.6 ≤
𝑥
< 5.6.32-78.1
perconapercona_server
5.7 ≤
𝑥
< 5.7.14-8
perconaxtradb_cluster
5.5 ≤
𝑥
< 5.5.41-37.0
perconaxtradb_cluster
5.6 ≤
𝑥
< 5.6.32-25.17
perconaxtradb_cluster
5.7 ≤
𝑥
< 5.7.14-26.17
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mariadb-10.0
yakkety
Fixed 10.0.29-0ubuntu0.16.10.1
released
xenial
Fixed 10.0.29-0ubuntu0.16.04.1
released
trusty
dne
precise
dne
mysql-5.5
yakkety
dne
xenial
dne
vivid
dne
trusty
Fixed 5.5.52-0ubuntu0.14.04.1
released
precise
Fixed 5.5.52-0ubuntu0.12.04.1
released
mysql-5.6
yakkety
dne
xenial
dne
trusty
dne
precise
dne
mysql-5.7
yakkety
not-affected
xenial
not-affected
trusty
dne
precise
dne
References