Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-6662
HistorySep 12, 2016 - 12:00 a.m.

CVE-2016-6662

2016-09-1200:00:00
ubuntu.com
ubuntu.com
17

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.009 Low

EPSS

Percentile

83.1%

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through
5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before
10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0,
and 5.7.x before 5.7.14-7 allow local users to create arbitrary
configurations and bypass certain protection mechanisms by setting
general_log_file to a my.cnf configuration. NOTE: this can be leveraged to
execute arbitrary code with root privileges by setting malloc_lib. NOTE:
the affected MySQL version information is from Oracle’s October 2016 CPU.
Oracle has not commented on third-party claims that the issue was silently
patched in MySQL 5.5.52, 5.6.33, and 5.7.15.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchmariadb-10.0<Β 10.0.27-0ubuntu0.16.04.1UNKNOWN
ubuntu16.10noarchmariadb-10.0<Β 10.0.28-0ubuntu0.16.10.1UNKNOWN
ubuntu14.04noarchmariadb-5.5<Β 5.5.52-1ubuntu0.14.04.1UNKNOWN
ubuntu12.04noarchmysql-5.5<Β 5.5.52-0ubuntu0.12.04.1UNKNOWN
ubuntu14.04noarchmysql-5.5<Β 5.5.52-0ubuntu0.14.04.1UNKNOWN
ubuntu14.04noarchmysql-5.6<Β 5.6.33-0ubuntu0.14.04.1UNKNOWN
ubuntu17.10noarchmysql-5.7<Β 5.7.15-0ubuntu2UNKNOWN
ubuntu18.04noarchmysql-5.7<Β 5.7.15-0ubuntu2UNKNOWN
ubuntu18.10noarchmysql-5.7<Β 5.7.15-0ubuntu2UNKNOWN
ubuntu19.04noarchmysql-5.7<Β 5.7.15-0ubuntu2UNKNOWN
Rows per page:
1-10 of 161

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.009 Low

EPSS

Percentile

83.1%