CVE-2016-6663

Description

Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17 allows local users with certain permissions to gain privileges by leveraging use of my_copystat by REPAIR TABLE to repair a MyISAM table.

Risk Information

Base Score
7.0
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.236

Associated Vulnerability

VulnerabilityOS Platform
Update MariaDB to 10.0.28Windows
Update MariaDB to 10.1.18Windows
Update MariaDB to 5.5.52Windows
Multiple vulnerabilities affected in Mysql 5.6.21Windows
Multiple vulnerabilities affected in Mysql 5.6.22Windows
Multiple vulnerabilities affected in Mysql 5.6.23Windows
Multiple vulnerabilities affected in Mysql 5.6.24Windows
Multiple vulnerabilities affected in Mysql 5.6.25Windows
Multiple vulnerabilities affected in Mysql 5.6.26Windows
Multiple vulnerabilities affected in Mysql 5.6.35Windows
Multiple vulnerabilities affected in Mysql 5.6.9Windows
Mysql security update (CESA-2017:0184) mysql-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-libs-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-libs-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-test-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-test-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-bench-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-bench-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-devel-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-devel-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-server-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-server-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-embedded-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-embedded-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql security update (CESA-2017:0184) mysql-embedded-devel-5.1.73-8.el6_8.i686.rpmLinux
Mysql security update (CESA-2017:0184) mysql-embedded-devel-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-bench-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-bench-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-devel-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-devel-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-embedded-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-embedded-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-embedded-devel-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-embedded-devel-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-libs-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-libs-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-server-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-server-5.1.73-8.el6_8.x86_64.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-test-5.1.73-8.el6_8.i686.rpmLinux
(RHSA-2017:0184) Important: mysql security update mysql-test-5.1.73-8.el6_8.x86_64.rpmLinux
Mysql update (ELSA-2017-0184) mysql-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-bench update (ELSA-2017-0184) mysql-bench-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-devel update (ELSA-2017-0184) mysql-devel-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-embedded update (ELSA-2017-0184) mysql-embedded-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-embedded-devel update (ELSA-2017-0184) mysql-embedded-devel-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-libs update (ELSA-2017-0184) mysql-libs-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-server update (ELSA-2017-0184) mysql-server-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql-test update (ELSA-2017-0184) mysql-test-5.1.73-8.0.1.el6_8.x86_64.rpmLinux
Mysql update (ELSA-2017-0184) mysql-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-bench update (ELSA-2017-0184) mysql-bench-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-devel update (ELSA-2017-0184) mysql-devel-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-embedded update (ELSA-2017-0184) mysql-embedded-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-embedded-devel update (ELSA-2017-0184) mysql-embedded-devel-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-libs update (ELSA-2017-0184) mysql-libs-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-server update (ELSA-2017-0184) mysql-server-5.1.73-8.0.1.el6_8.i686.rpmLinux
Mysql-test update (ELSA-2017-0184) mysql-test-5.1.73-8.0.1.el6_8.i686.rpmLinux
Update MariaDB to 10.0.28 (For Linux)Linux
Update MariaDB to 10.1.18 (For Linux)Linux
Update MariaDB to 5.5.52 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.21 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.22 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.23 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.24 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.25 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.26 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.35 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.9 (For Linux)Linux
Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) Vulnerability (CVE-2016-6663)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234