Executive Summary
Summary | |
---|---|
Title | mariadb-galera security update |
Informations | |||
---|---|---|---|
Name | RHSA-2016:2062 | First vendor Publication | 2016-10-13 |
Vendor | RedHat | Last vendor Modification | 2016-10-13 |
Severity (Vendor) | N/A | Revision | 01 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: An update for mariadb-galera is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 9.0 - x86_64 3. Description: MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. Galera is a synchronous multi-master cluster for MariaDB. Security Fix(es): * A permissions flaw was discovered in the MySQL logging functionality, which allowed writing to MySQL configuration files. An administrative database user, or a database user with FILE privileges, could possibly exploit this flaw to run arbitrary commands with root privileges on the system running the database server. (CVE-2016-6662) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the MariaDB server daemon (mysqld) will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1375198 - CVE-2016-6662 mysql: general_log can write to configuration files, leading to privilege escalation |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2016-2062.html |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
CPE : Common Platform Enumeration
Snort® IPS/IDS
Date | Description |
---|---|
2016-10-25 | Multiple SQL products privilege escalation attempt RuleID : 40254 - Revision : 2 - Type : SERVER-MYSQL |
2016-10-25 | Multiple SQL products privilege escalation attempt RuleID : 40253 - Revision : 2 - Type : SERVER-MYSQL |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2017-07-13 | Name : The remote Virtuozzo host is missing a security update. File : Virtuozzo_VZLSA-2017-0184.nasl - Type : ACT_GATHER_INFO |
2017-05-01 | Name : The remote EulerOS host is missing multiple security updates. File : EulerOS_SA-2016-1062.nasl - Type : ACT_GATHER_INFO |
2017-02-23 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2017-800.nasl - Type : ACT_GATHER_INFO |
2017-01-27 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2017-0184.nasl - Type : ACT_GATHER_INFO |
2017-01-26 | Name : The remote OracleVM host is missing a security update. File : oraclevm_OVMSA-2017-0035.nasl - Type : ACT_GATHER_INFO |
2017-01-25 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20170124_mysql_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2017-01-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2017-0184.nasl - Type : ACT_GATHER_INFO |
2017-01-25 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2017-0184.nasl - Type : ACT_GATHER_INFO |
2017-01-03 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201701-01.nasl - Type : ACT_GATHER_INFO |
2016-12-15 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20161103_mariadb_on_SL7_x.nasl - Type : ACT_GATHER_INFO |
2016-11-28 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2016-2595.nasl - Type : ACT_GATHER_INFO |
2016-11-25 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_dc596a177a9e11e6b034f0def167eeea.nasl - Type : ACT_GATHER_INFO |
2016-11-14 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2780-1.nasl - Type : ACT_GATHER_INFO |
2016-11-14 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1289.nasl - Type : ACT_GATHER_INFO |
2016-11-11 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-2595.nasl - Type : ACT_GATHER_INFO |
2016-11-11 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1283.nasl - Type : ACT_GATHER_INFO |
2016-11-09 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1274.nasl - Type : ACT_GATHER_INFO |
2016-11-04 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-2595.nasl - Type : ACT_GATHER_INFO |
2016-10-21 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_5_53_rpm.nasl - Type : ACT_GATHER_INFO |
2016-10-21 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_7_16_rpm.nasl - Type : ACT_GATHER_INFO |
2016-10-21 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_6_34_rpm.nasl - Type : ACT_GATHER_INFO |
2016-10-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_5_53.nasl - Type : ACT_GATHER_INFO |
2016-10-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_6_34.nasl - Type : ACT_GATHER_INFO |
2016-10-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_7_16.nasl - Type : ACT_GATHER_INFO |
2016-10-13 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2016-756.nasl - Type : ACT_GATHER_INFO |
2016-10-06 | Name : The remote Fedora host is missing a security update. File : fedora_2016-58f90ae3cc.nasl - Type : ACT_GATHER_INFO |
2016-10-05 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1154.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2404-1.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2395-1.nasl - Type : ACT_GATHER_INFO |
2016-09-27 | Name : The remote Fedora host is missing a security update. File : fedora_2016-0901301dff.nasl - Type : ACT_GATHER_INFO |
2016-09-21 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2343-1.nasl - Type : ACT_GATHER_INFO |
2016-09-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mariadb_10_1_17.nasl - Type : ACT_GATHER_INFO |
2016-09-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mariadb_10_0_27.nasl - Type : ACT_GATHER_INFO |
2016-09-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mariadb_5_5_51.nasl - Type : ACT_GATHER_INFO |
2016-09-19 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_b64a73897c2711e68aaa5404a68ad561.nasl - Type : ACT_GATHER_INFO |
2016-09-19 | Name : The remote Debian host is missing a security update. File : debian_DLA-624.nasl - Type : ACT_GATHER_INFO |
2016-09-15 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3078-1.nasl - Type : ACT_GATHER_INFO |
2016-09-15 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_856b88bf798411e681e7d050996490d0.nasl - Type : ACT_GATHER_INFO |
2016-09-15 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3666.nasl - Type : ACT_GATHER_INFO |
2016-09-15 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2016-257-01.nasl - Type : ACT_GATHER_INFO |
2016-09-08 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_5_52.nasl - Type : ACT_GATHER_INFO |
2016-09-08 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_7_15_rpm.nasl - Type : ACT_GATHER_INFO |
2016-09-08 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_7_15.nasl - Type : ACT_GATHER_INFO |
2016-09-08 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_6_33_rpm.nasl - Type : ACT_GATHER_INFO |
2016-09-08 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_6_33.nasl - Type : ACT_GATHER_INFO |
2016-09-08 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_5_52_rpm.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2016-10-14 00:23:27 |
|