|
|
Log in / Subscribe / Register

mysql: SQL injection/privilege escalation

Package(s):mysql mariadb CVE #(s):CVE-2016-6662
Created:September 14, 2016 Updated:November 11, 2016
Description: From the legalhackers advisory:

An independent research has revealed multiple severe MySQL vulnerabilities. This advisory focuses on a critical vulnerability with a CVEID of CVE-2016-6662 which can allow attackers to (remotely) inject malicious settings into MySQL configuration files (my.cnf) leading to critical consequences.

The vulnerability affects all MySQL servers in default configuration in all version branches (5.7, 5.6, and 5.5) including the latest versions, and could be exploited by both local and remote attackers. Both the authenticated access to MySQL database (via network connection or web interfaces such as phpMyAdmin) and SQL Injection could be used as exploitation vectors.

As SQL Injection attacks are one of the most common issues in web applications, the CVE-2016-6662 vulnerability could put web applications at a critical risk in case of a successful SQL Injection attack.

A successful exploitation could allow attackers to execute arbitrary code with root privileges which would then allow them to fully compromise the server on which an affected version of MySQL is running.

Alerts:
Red Hat RHSA-2016:2749-01 rh-mysql56-mysql 2016-11-15
SUSE SUSE-SU-2016:2780-1 mysql 2016-11-12
openSUSE openSUSE-SU-2016:2788-1 mysql-community-server 2016-11-12
Oracle ELSA-2016-2595 mariadb 2016-11-10
openSUSE openSUSE-SU-2016:2769-1 mysql-community-server 2016-11-10
openSUSE openSUSE-SU-2016:2746-1 mariadb 2016-11-08
Red Hat RHSA-2016:2595-02 mariadb 2016-11-03
Red Hat RHSA-2016:2130-01 mysql55-mysql 2016-10-31
Red Hat RHSA-2016:2131-01 mariadb55-mariadb 2016-10-31
Red Hat RHSA-2016:2077-01 mariadb-galera 2016-10-18
Red Hat RHSA-2016:2058-01 mariadb-galera 2016-10-13
Red Hat RHSA-2016:2059-01 mariadb-galera 2016-10-13
Red Hat RHSA-2016:2060-01 mariadb-galera 2016-10-13
Red Hat RHSA-2016:2061-01 mariadb-galera 2016-10-13
Red Hat RHSA-2016:2062-01 mariadb-galera 2016-10-13
openSUSE openSUSE-SU-2016:2448-1 mariadb 2016-10-04
Fedora FEDORA-2016-58f90ae3cc mariadb 2016-10-03
SUSE SUSE-SU-2016:2395-1 mariadb 2016-09-27
SUSE SUSE-SU-2016:2404-1 mariadb 2016-09-27
Fedora FEDORA-2016-0901301dff community-mysql 2016-09-27
SUSE SUSE-SU-2016:2343-1 mysql 2016-09-20
Debian-LTS DLA-624-1 mysql-5.5 2016-09-16
Arch Linux ASA-201609-10 mariadb 2016-09-14
Ubuntu USN-3078-1 mysql-5.5, mysql-5.7 2016-09-13
Slackware SSA:2016-257-01 mariadb 2016-09-13
Debian DSA-3666-1 mysql-5.5 2016-09-14
CentOS CESA-2017:0184 mysql 2017-01-26
Oracle ELSA-2017-0184 mysql 2017-01-24
Scientific Linux SLSA-2017:0184-1 mysql 2017-01-24
Red Hat RHSA-2017:0184-01 mysql 2017-01-24
Gentoo 201701-01 mariadb 2017-01-01
Scientific Linux SLSA-2016:2595-2 mariadb 2016-12-14
Red Hat RHSA-2016:2928-01 rh-mariadb101-mariadb 2016-12-08
Red Hat RHSA-2016:2927-01 rh-mariadb100-mariadb 2016-12-08

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds