CVE-2016-6664
Summary
| CVE | CVE-2016-6664 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-12-13 21:59:00 UTC |
| Updated | 2023-01-24 16:09:00 UTC |
| Description | mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| MySQL / MariaDB / PerconaDB 5.5.x/5.6.x/5.7.x - 'root' Privilege Escalation |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Third Party Advisory, VDB Entry |
| Oracle MySQL CVE-2016-6664 Local Security Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Percona responds to CVE-2016-6663 and CVE-2016-6664 - Percona Database Performance Blog |
CONFIRM |
www.percona.com |
Vendor Advisory |
| Oracle Critical Patch Update - October 2016 |
CONFIRM |
www.oracle.com |
Patch, Vendor Advisory |
| Full Disclosure: MySQL / MariaDB / PerconaDB - Privilege Escalation / Race Condition Exploit [CVE-2016-6663 / OCVE-2016-5616] |
FULLDISC |
seclists.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| MariaDB: Multiple vulnerabilities (GLSA 201702-18) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Debian -- Security Information -- DSA-3770-1 mariadb-10.0 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| SecurityFocus |
BUGTRAQ |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| MySQL / MariaDB / PerconaDB Root Privilege Escalation ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Exploit, Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| MySQL-Maria-Percona-RootPrivEsc-CVE-2016-6664-5617-Exploit |
MISC |
legalhackers.com |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500374 Alpine Linux Security Update for mariadb
- 504132 Alpine Linux Security Update for mariadb
- 710361 Gentoo Linux MariaDB Multiple Vulnerabilities (GLSA 201702-18)
- 900121 CBL-Mariner Linux Security Update for mariadb 10.3.17
- 903092 Common Base Linux Mariner (CBL-Mariner) Security Update for mariadb (2680)