RHSA-2017:0184-01 -- Redhat mysqlID: oval:org.secpod.oval:def:501968 | Date: (C)2017-01-25 (M)2023-12-20 |
Class: PATCH | Family: unix |
MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon and many client programs and libraries. Security Fix: * It was discovered that the MySQL logging functionality allowed writing to MySQL configuration files. An administrative database user, or a database user with FILE privileges, could possibly use this flaw to run arbitrary commands with root privileges on the system running the database server. * A race condition was found in the way MySQL performed MyISAM engine table repair. A database user with shell access to the server running mysqld could use this flaw to change permissions of arbitrary files writable by the mysql system user
Platform: |
Red Hat Enterprise Linux 6 |