Lucene search

K
cloudfoundryCloud FoundryCFOUNDRY:8FC4D407A8F6487531A7FC5466D01C69
HistorySep 28, 2016 - 12:00 a.m.

CVE-2016-6662 - Multiple MySQL Vulnerabilities | Cloud Foundry

2016-09-2800:00:00
Cloud Foundry
www.cloudfoundry.org
33

0.009 Low

EPSS

Percentile

83.1%

CVE-2016-6662 – Multiple MySQL Vulnerabilities

Medium

Vendor

Cloud Foundry Foundation, MariaDB

Versions Affected

  • MariaDB versions prior to 10.1.17
  • cf-mysql versions prior to v29

Description

The Cloud Foundry MySQL team recently completed an upgrade of MariaDB to 10.1.17, which includes a large number of CVEs, including:

  • Dawid Golunski discovered that MySQL incorrectly handled configuration files. A remote attacker could possibly use this issue to execute arbitrary code with root privileges. (CVE-2016-6662) [1]
  • The full list of CVEs fixed in MariaDB 10.1.17 and earlier versions can be found on their website [2].

Mitigation

OSS users are strongly encouraged to follow one of the mitigations below:

  • Upgrade to cf-mysql-release v29+ [3]

References