Oracle MySQL is vulnerable to improper access control. MySQL init script mishandles initialization of the database data directory and permission setting on the error log file allowing local attackers to escalate their privileges to root or cause a system crash.
www.debian.org/security/2017/dsa-3767
www.debian.org/security/2017/dsa-3770
www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html#AppendixMSQL
www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html
www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixMSQL
www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixMSQL
www.securityfocus.com/bid/95520
www.securitytracker.com/id/1037640
access.redhat.com/errata/RHSA-2017:2192
access.redhat.com/errata/RHSA-2017:2787
access.redhat.com/errata/RHSA-2018:0279
access.redhat.com/errata/RHSA-2018:0574
access.redhat.com/security/updates/classification/#important
bugzilla.redhat.com/show_bug.cgi?id=1477575
bugzilla.redhat.com/show_bug.cgi?id=1482122
dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-35.html
dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-36.html
dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-37.html
security.gentoo.org/glsa/201702-17
security.gentoo.org/glsa/201702-18