[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2017-800 ---- mysql51

ID: oval:org.secpod.oval:def:1600506Date: (C)2017-03-21   (M)2023-12-20
Class: PATCHFamily: unix




It was discovered that the MySQL logging functionality allowed writing to MySQL configuration files. An administrative database user, or a database user with FILE privileges, could possibly use this flaw to run arbitrary commands with root privileges on the system running the database server. A race condition was found in the way MySQL performed MyISAM engine table repair. A database user with shell access to the server running mysqld could use this flaw to change permissions of arbitrary files writable by the mysql system user

Platform:
Amazon Linux AMI
Product:
mysql51
Reference:
ALAS-2017-800
CVE-2016-6662
CVE-2016-6663
CVE    2
CVE-2016-6663
CVE-2016-6662
CPE    2
cpe:/o:amazon:linux
cpe:/a:mysql:mysql51

© SecPod Technologies