[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-0546Date: (C)2016-02-11   (M)2024-04-19


Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that these are multiple buffer overflows in the mysqlshow tool that allow remote database servers to have unspecified impact via a long table or database name.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1034708
BID-81066
DSA-3453
DSA-3459
RHSA-2016:0534
RHSA-2016:0705
RHSA-2016:1132
RHSA-2016:1480
RHSA-2016:1481
SUSE-SU-2016:1619
SUSE-SU-2016:1620
USN-2881-1
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
https://bugzilla.redhat.com/show_bug.cgi?id=1301493
https://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-47.html
https://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-28.html
https://github.com/mysql/mysql-server/commit/0dbd5a8797ed4bd18e8b883988fb62177eb0f73f
https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/
https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/
https://mariadb.com/kb/en/mdb-10023-rn/
openSUSE-SU-2016:0367
openSUSE-SU-2016:0377
openSUSE-SU-2016:1664
openSUSE-SU-2016:1686

CPE    13
cpe:/o:redhat:enterprise_linux_hpc_node:7.0
cpe:/o:debian:debian_linux:8.0
cpe:/a:oracle:mysql
cpe:/o:redhat:enterprise_linux:7.0
...
OVAL    23
oval:org.secpod.oval:def:504971
oval:org.secpod.oval:def:1600443
oval:org.secpod.oval:def:602353
oval:org.secpod.oval:def:89045145
...

© SecPod Technologies