← All CVEs

CVE-2016-6662

critical · 9.8

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.

9.8
CVSS
67.7%
EPSS (exploit prob.)
99th
EPSS percentile
2016-09-20
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
oraclemysql>= 5.5.0, <= 5.5.52
oraclemysql>= 5.6.0, <= 5.6.33
oraclemysql>= 5.7.0, <= 5.7.15
perconapercona_server>= 5.5, < 5.5.51-38.1
perconapercona_server>= 5.6, < 5.6.32-78.0
perconapercona_server>= 5.7, < 5.7.14-7
mariadbmariadb>= 5.5.20, < 5.5.51
mariadbmariadb>= 10.0.0, < 10.0.27
mariadbmariadb>= 10.1.0, < 10.1.17
debiandebian_linux8.0
redhatopenstack5.0
redhatopenstack6.0
redhatopenstack7.0
redhatopenstack8
redhatopenstack9
redhatenterprise_linux7.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_aus7.3
redhatenterprise_linux_server_aus7.4
redhatenterprise_linux_server_aus7.6
redhatenterprise_linux_server_eus7.3
redhatenterprise_linux_server_eus7.4
redhatenterprise_linux_server_eus7.5
redhatenterprise_linux_server_eus7.6
redhatenterprise_linux_server_tus7.3
redhatenterprise_linux_server_tus7.6
redhatenterprise_linux_workstation6.0
redhatenterprise_linux_workstation7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-6662