CVE-2016-6662

Description

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracles October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
89.577

Associated Vulnerability

VulnerabilityOS Platform
Update MariaDB to 10.0.27Windows
Update MariaDB to 10.1.17Windows
Update MariaDB to 5.5.51Windows
Multiple vulnerabilities affected in Mysql 5.6.21Windows
Multiple vulnerabilities affected in Mysql 5.6.22Windows
Multiple vulnerabilities affected in Mysql 5.6.23Windows
Multiple vulnerabilities affected in Mysql 5.6.24Windows
Multiple vulnerabilities affected in Mysql 5.6.25Windows
Multiple vulnerabilities affected in Mysql 5.6.26Windows
Multiple vulnerabilities affected in Mysql 5.6.35Windows
Multiple vulnerabilities affected in Mysql 5.6.9Windows
Vulnerabilities CVE-2016-5584,CVE-2016-6662,CVE-2016-7440 are affected in Mysql earlierWindows
Vulnerabilities CVE-2016-5584,CVE-2016-6304,CVE-2016-6662,CVE-2016-7440 are affected in Mysql earlierWindows
MySQL database (USN-3078-1) mysql-server-5.5_5.5.52-0ubuntu0.12.04.1_i386.debLinux
MySQL database (USN-3078-1) mysql-server-5.5_5.5.52-0ubuntu0.12.04.1_amd64.debLinux
MySQL database (USN-3078-1) mysql-server-5.5_5.5.52-0ubuntu0.14.04.1_i386.debLinux
MySQL database (USN-3078-1) mysql-server-5.5_5.5.52-0ubuntu0.14.04.1_amd64.debLinux
MySQL database (USN-3078-1) mysql-server-5.7_5.7.15-0ubuntu0.16.04.1_i386.debLinux
MySQL database (USN-3078-1) mysql-server-5.7_5.7.15-0ubuntu0.16.04.1_amd64.debLinux
Mysql security update (CESA-2017:0184) mysql-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-libs-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-libs-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-test-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-test-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-bench-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-bench-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-devel-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-devel-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-server-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-server-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-embedded-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-embedded-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-embedded-devel-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-embedded-devel-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-bench-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-bench-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-devel-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-devel-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-embedded-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-embedded-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-embedded-devel-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-embedded-devel-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-libs-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-libs-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-server-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-server-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-test-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-test-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql update (ELSA-2017-0184) mysql-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-bench update (ELSA-2017-0184) mysql-bench-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-devel update (ELSA-2017-0184) mysql-devel-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-embedded update (ELSA-2017-0184) mysql-embedded-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-embedded-devel update (ELSA-2017-0184) mysql-embedded-devel-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-libs update (ELSA-2017-0184) mysql-libs-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-server update (ELSA-2017-0184) mysql-server-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-test update (ELSA-2017-0184) mysql-test-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql update (ELSA-2017-0184) mysql-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-bench update (ELSA-2017-0184) mysql-bench-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-devel update (ELSA-2017-0184) mysql-devel-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-embedded update (ELSA-2017-0184) mysql-embedded-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-embedded-devel update (ELSA-2017-0184) mysql-embedded-devel-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-libs update (ELSA-2017-0184) mysql-libs-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-server update (ELSA-2017-0184) mysql-server-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-test update (ELSA-2017-0184) mysql-test-5.1.73-8.0.1.el6_8.i686.rpmLinux
Update MariaDB to 10.0.27 (For Linux)Linux
Update MariaDB to 10.1.17 (For Linux)Linux
Update MariaDB to 5.5.51 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.21 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.22 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.23 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.24 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.25 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.26 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.35 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.9 (For Linux)Linux
CVE-2016-6662NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234