CVE Vulnerabilities

CVE-2016-6662

Published: Sep 20, 2016 | Modified: Apr 12, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.1 IMPORTANT
AV:N/AC:H/Au:S/C:C/I:C/A:C
RedHat/V3
9.8 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracles October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.

Affected Software

NameVendorStart VersionEnd Version
MysqlOracle5.5.0 (including)5.5.52 (including)
MysqlOracle5.6.0 (including)5.6.33 (including)
MysqlOracle5.7.0 (including)5.7.15 (including)
Red Hat Enterprise Linux 6RedHatmysql-0:5.1.73-8.el6_8*
Red Hat Enterprise Linux 7RedHatmariadb-1:5.5.52-1.el7*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatmariadb-galera-0:5.5.42-1.1.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatmariadb-galera-1:5.5.42-1.2.el7ost*
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatmariadb-galera-1:5.5.42-1.2.el7ost*
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7RedHatmariadb-galera-1:5.5.42-5.el7ost*
Red Hat OpenStack Platform 8.0 (Liberty)RedHatmariadb-galera-1:5.5.42-5.el7ost*
Red Hat OpenStack Platform 9.0 (Mitaka)RedHatmariadb-galera-1:5.5.42-5.el7ost*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatmysql55-mysql-0:5.5.52-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatmariadb55-mariadb-0:5.5.53-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-mysql56-mysql-0:5.6.34-2.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-mariadb100-mariadb-1:10.0.28-5.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-mariadb101-mariadb-1:10.1.19-6.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatmysql55-mysql-0:5.5.52-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHatmariadb55-mariadb-0:5.5.53-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatmysql55-mysql-0:5.5.52-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatmariadb55-mariadb-0:5.5.53-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-mysql56-mysql-0:5.6.34-2.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-mariadb100-mariadb-1:10.0.28-5.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-mariadb101-mariadb-1:10.1.19-6.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatmysql55-mysql-0:5.5.52-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatmariadb55-mariadb-0:5.5.53-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mysql56-mysql-0:5.6.34-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb100-mariadb-1:10.0.28-5.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb101-mariadb-1:10.1.19-6.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatmysql55-mysql-0:5.5.52-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatmariadb55-mariadb-0:5.5.53-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-mysql56-mysql-0:5.6.34-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatmysql55-mysql-0:5.5.52-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatmariadb55-mariadb-0:5.5.53-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-mysql56-mysql-0:5.6.34-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-mariadb100-mariadb-1:10.0.28-5.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-mariadb101-mariadb-1:10.1.19-6.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSRedHatrh-mariadb100-mariadb-1:10.0.28-5.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSRedHatrh-mariadb101-mariadb-1:10.1.19-6.el7*
Mariadb-10.0Ubuntuesm-apps/xenial*
Mariadb-10.0Ubuntuupstream*
Mariadb-10.0Ubuntuxenial*
Mariadb-10.0Ubuntuyakkety*
Mariadb-5.5Ubuntutrusty*
Mysql-5.5Ubuntuesm-infra-legacy/trusty*
Mysql-5.5Ubuntuprecise*
Mysql-5.5Ubuntutrusty*
Mysql-5.5Ubuntutrusty/esm*
Mysql-5.5Ubuntuupstream*
Mysql-5.6Ubuntutrusty*
Mysql-5.6Ubuntuupstream*
Mysql-5.7Ubuntuartful*
Mysql-5.7Ubuntubionic*
Mysql-5.7Ubuntucosmic*
Mysql-5.7Ubuntudisco*
Mysql-5.7Ubuntuesm-infra/bionic*
Mysql-5.7Ubuntuesm-infra/xenial*
Mysql-5.7Ubuntuupstream*
Mysql-5.7Ubuntuxenial*
Mysql-5.7Ubuntuyakkety*
Mysql-5.7Ubuntuzesty*
Percona-server-5.6Ubuntuartful*
Percona-server-5.6Ubuntuesm-apps/xenial*
Percona-server-5.6Ubuntuxenial*
Percona-server-5.6Ubuntuyakkety*
Percona-server-5.6Ubuntuzesty*
Percona-xtradb-cluster-5.5Ubuntutrusty*
Percona-xtradb-cluster-5.6Ubuntuesm-apps/xenial*
Percona-xtradb-cluster-5.6Ubuntuxenial*
Percona-xtradb-cluster-5.6Ubuntuyakkety*

References