Critical vulnerability discovered in MySQL application
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-6662 | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15. NVD description · AI analysis pending | 9.8 | 68% | PoC |
| — |
Full article586 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A researcher has discovered a critical security flaw in the world's most widely used open-source database application — one that could allow hackers to completely take over a web server.
A researcher has discovered a critical security flaw in the world’s most widely used open-source database application — one that could allow hackers to completely take over a web server.
And, because Oracle is dragging its feet in releasing a patch and word of the flaw was starting to leak out, the researcher — Dawid Golunski — went ahead Tuesday and published details of the vulnerability and a partial proof of concept.
The vulnerability affects every version of Oracle’s MySQL application and two clones of it — MariaDB and PerconaDB.
The vulnerability, designated CVE-2016-6662, could potentially allow an attacker “to execute arbitrary code with root privileges which would then allow them to fully compromise the server on which an affected version of MySQL is running,” wrote Golunski in a post laying out details of his discovery.
He said the vulnerability could be exploited locally or remotely, via SQL injection.
He said that — in line with responsible disclosure best practice — he privately told Oracle and the manufacturers of PerconaDB and MariaDB about the vulnerability on July 29.
PerconaDB and MariaDB were both patched by their vendors on August 30, he said, but “Official patches for the vulnerability are not available at this time for Oracle MySQL server.”
Because the documentation accompanying the patches for PerconaDB and MariaDB contained details that could enable hackers to reverse-engineer the vulnerability, and because over 40 days had elapsed, Golunski said he made the decision to release details of the vulnerability and limited proof-of-concept code “to inform users about the risks” before Oracle’s next update — not scheduled until next month.
Oracle declined to comment.
On one security forum there were some expressions of skepticism about the seriousness of the vulnerability, given that the hacker trying to make use of it would require certain kinds of system privileges.
“This doesn’t seem very threatening at all,” wrote one user, “If you’re not already running services with strict file permissions this is the least of your worries.”
The user added that the vulnerability was better described as privilege escalation, a lesser kind of security flaw, rather than remote code execution.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/mysql-vulnerability-perconadb-mariadb/