CVE-2020-7221
Summary
| CVE | CVE-2020-7221 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-04 17:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 1160868 – VUL-0: CVE-2020-7221: mariadb: auth_pam_tool runtime permission setting allows privilege escalation from mysql user to root | MISC | bugzilla.suse.com | Exploit, Issue Tracking, Third Party Advisory |
| oss-sec: CVE-2020-7221: mariadb: possible local mysql to root user exploit in mysql_install_db script setting permissions of /usr/lib64/mysql/plugin/auth_pam_tool_dir/auth_pam_tool | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| rpm/deb and auth_pam_tool_dir/auth_pam_tool · MariaDB/server@9d18b62 · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.