CVE-2016-6664

Description

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.

Risk Information

Base Score
7.0
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
47.117

Associated Vulnerability

VulnerabilityOS Platform
Update MariaDB to 10.0.29Windows
Update MariaDB to 10.1.21Windows
Update MariaDB to 5.5.54Windows
Multiple vulnerabilities affected in Mysql 5.6.21Windows
Multiple vulnerabilities affected in Mysql 5.6.22Windows
Multiple vulnerabilities affected in Mysql 5.6.23Windows
Multiple vulnerabilities affected in Mysql 5.6.24Windows
Multiple vulnerabilities affected in Mysql 5.6.25Windows
Multiple vulnerabilities affected in Mysql 5.6.26Windows
Multiple vulnerabilities affected in Mysql 5.6.35Windows
Multiple vulnerabilities affected in Mysql 5.6.9Windows
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-5.5.56-2.el7.x86_64.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-bench-5.5.56-2.el7.x86_64.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-devel-5.5.56-2.el7.i686.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-devel-5.5.56-2.el7.x86_64.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-embedded-5.5.56-2.el7.i686.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-embedded-5.5.56-2.el7.x86_64.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-embedded-devel-5.5.56-2.el7.i686.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-embedded-devel-5.5.56-2.el7.x86_64.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-libs-5.5.56-2.el7.i686.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-libs-5.5.56-2.el7.x86_64.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-server-5.5.56-2.el7.x86_64.rpmLinux
(RHSA-2017:2192) Moderate: mariadb security and bug fix update mariadb-test-5.5.56-2.el7.x86_64.rpmLinux
Update MariaDB to 10.0.29 (For Linux)Linux
Update MariaDB to 10.1.21 (For Linux)Linux
Update MariaDB to 5.5.54 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.21 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.22 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.23 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.24 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.25 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.26 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.35 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 5.6.9 (For Linux)Linux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-5.5.56-2.el7.x86_64.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-bench-5.5.56-2.el7.x86_64.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-devel-5.5.56-2.el7.i686.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-devel-5.5.56-2.el7.x86_64.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-embedded-5.5.56-2.el7.i686.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-embedded-5.5.56-2.el7.x86_64.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-embedded-devel-5.5.56-2.el7.i686.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-embedded-devel-5.5.56-2.el7.x86_64.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-libs-5.5.56-2.el7.i686.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-libs-5.5.56-2.el7.x86_64.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-server-5.5.56-2.el7.x86_64.rpmLinux
(CESA-2017:2192) Moderate: mariadb security and bug fix update mariadb-test-5.5.56-2.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234