CVE-2016-6662 (mariadb, mysql, percona_server)

CVE-2016-6662 (mariadb, mysql, percona_server)

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib.

Source: CVE-2016-6662 (mariadb, mysql, percona_server)

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다