ELSA-2016-2595 -- Oracle mariadbID: oval:org.secpod.oval:def:1501640 | Date: (C)2016-12-07 (M)2023-12-20 |
Class: PATCH | Family: unix |
MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. The following packages have been upgraded to a newer upstream version: mariadb . Security Fix: * It was discovered that the MariaDB logging functionality allowed writing to MariaDB configuration files. An administrative database user, or a database user with FILE privileges, could possibly use this flaw to run arbitrary commands with root privileges on the system running the database server. * A race condition was found in the way MariaDB performed MyISAM engine table repair. A database user with shell access to the server running mysqld could use this flaw to change permissions of arbitrary files writable by the mysql system user. * This update fixes several vulnerabilities in the MariaDB database server.