[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2016-2595 -- Oracle mariadb

ID: oval:org.secpod.oval:def:1501640Date: (C)2016-12-07   (M)2023-12-20
Class: PATCHFamily: unix




MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. The following packages have been upgraded to a newer upstream version: mariadb . Security Fix: * It was discovered that the MariaDB logging functionality allowed writing to MariaDB configuration files. An administrative database user, or a database user with FILE privileges, could possibly use this flaw to run arbitrary commands with root privileges on the system running the database server. * A race condition was found in the way MariaDB performed MyISAM engine table repair. A database user with shell access to the server running mysqld could use this flaw to change permissions of arbitrary files writable by the mysql system user. * This update fixes several vulnerabilities in the MariaDB database server.

Platform:
Oracle Linux 7
Product:
mariadb
Reference:
ELSA-2016-2595
CVE-2016-3492
CVE-2016-5612
CVE-2016-5624
CVE-2016-5626
CVE-2016-5629
CVE-2016-6662
CVE-2016-6663
CVE-2016-8283
CVE    8
CVE-2016-5626
CVE-2016-6663
CVE-2016-6662
CVE-2016-3492
...
CPE    2
cpe:/o:oracle:linux:7
cpe:/a:mariadb:mariadb

© SecPod Technologies