mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mysql | Oracle | 5.5.0 (including) | 5.5.51 (including) |
Mysql | Oracle | 5.6.0 (including) | 5.6.32 (including) |
Mysql | Oracle | 5.7.0 (including) | 5.7.14 (including) |
Red Hat Enterprise Linux 7 | RedHat | mariadb-1:5.5.56-2.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | mysql55-mysql-0:5.5.52-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-mysql56-mysql-0:5.6.34-2.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-mariadb100-mariadb-1:10.0.33-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-mariadb101-galera-0:25.3.12-12.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-mariadb101-mariadb-1:10.1.29-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | mysql55-mysql-0:5.5.52-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | mysql55-mysql-0:5.5.52-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-mysql56-mysql-0:5.6.34-2.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-mariadb100-mariadb-1:10.0.33-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-mariadb101-galera-0:25.3.12-12.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-mariadb101-mariadb-1:10.1.29-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | mysql55-mysql-0:5.5.52-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-mysql56-mysql-0:5.6.34-2.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-mariadb100-mariadb-1:10.0.33-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-mariadb101-galera-0:25.3.12-12.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-mariadb101-mariadb-1:10.1.29-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | mysql55-mysql-0:5.5.52-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | RedHat | rh-mysql56-mysql-0:5.6.34-2.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | mysql55-mysql-0:5.5.52-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | rh-mysql56-mysql-0:5.6.34-2.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-mariadb100-mariadb-1:10.0.33-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-mariadb101-galera-0:25.3.12-12.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-mariadb101-mariadb-1:10.1.29-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-mariadb100-mariadb-1:10.0.33-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-mariadb101-galera-0:25.3.12-12.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-mariadb101-mariadb-1:10.1.29-3.el7 | * |
Mariadb-10.0 | Ubuntu | upstream | * |
Mariadb-10.0 | Ubuntu | xenial | * |
Mariadb-10.0 | Ubuntu | yakkety | * |
Mysql-5.5 | Ubuntu | precise | * |
Mysql-5.5 | Ubuntu | trusty | * |
Mysql-5.5 | Ubuntu | upstream | * |
Mysql-5.6 | Ubuntu | upstream | * |
Mysql-5.7 | Ubuntu | upstream | * |