Oval Definition:oval:com.redhat.rhsa:def:20162595
Revision Date:2016-11-03Version:646
Title:RHSA-2016:2595: mariadb security and bug fix update (Important)
Description:MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL.

  • The following packages have been upgraded to a newer upstream version: mariadb (5.5.52). (BZ#1304516, BZ#1377974)

    Security Fix(es):

  • It was discovered that the MariaDB logging functionality allowed writing to MariaDB configuration files. An administrative database user, or a database user with FILE privileges, could possibly use this flaw to run arbitrary commands with root privileges on the system running the database server. (CVE-2016-6662)

  • A race condition was found in the way MariaDB performed MyISAM engine table repair. A database user with shell access to the server running mysqld could use this flaw to change permissions of arbitrary files writable by the mysql system user. (CVE-2016-6663)

  • This update fixes several vulnerabilities in the MariaDB database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section. (CVE-2016-3492, CVE-2016-5612, CVE-2016-5616, CVE-2016-5624, CVE-2016-5626, CVE-2016-5629, CVE-2016-8283)

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-3492
    CVE-2016-5612
    CVE-2016-5616
    CVE-2016-5624
    CVE-2016-5626
    CVE-2016-5629
    CVE-2016-6662
    CVE-2016-6663
    CVE-2016-8283
    RHSA-2016:2595
    RHSA-2016:2595-01
    RHSA-2016:2595-02
    RHSA-2016:2595-02
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • mariadb is earlier than 1:5.5.52-1.el7
  • AND mariadb is signed with Red Hat redhatrelease2 key
  • mariadb-bench is earlier than 1:5.5.52-1.el7
  • AND mariadb-bench is signed with Red Hat redhatrelease2 key
  • mariadb-devel is earlier than 1:5.5.52-1.el7
  • AND mariadb-devel is signed with Red Hat redhatrelease2 key
  • mariadb-embedded is earlier than 1:5.5.52-1.el7
  • AND mariadb-embedded is signed with Red Hat redhatrelease2 key
  • mariadb-embedded-devel is earlier than 1:5.5.52-1.el7
  • AND mariadb-embedded-devel is signed with Red Hat redhatrelease2 key
  • mariadb-libs is earlier than 1:5.5.52-1.el7
  • AND mariadb-libs is signed with Red Hat redhatrelease2 key
  • mariadb-server is earlier than 1:5.5.52-1.el7
  • AND mariadb-server is signed with Red Hat redhatrelease2 key
  • mariadb-test is earlier than 1:5.5.52-1.el7
  • AND mariadb-test is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • mariadb-embedded-devel is earlier than 1:5.5.52-1.el7
  • AND mariadb-embedded-devel is signed with Red Hat redhatrelease2 key
  • OR
  • mariadb-embedded is earlier than 1:5.5.52-1.el7
  • AND mariadb-embedded is signed with Red Hat redhatrelease2 key
  • OR
  • mariadb is earlier than 1:5.5.52-1.el7
  • AND mariadb is signed with Red Hat redhatrelease2 key
  • OR
  • mariadb-bench is earlier than 1:5.5.52-1.el7
  • AND mariadb-bench is signed with Red Hat redhatrelease2 key
  • OR
  • mariadb-devel is earlier than 1:5.5.52-1.el7
  • AND mariadb-devel is signed with Red Hat redhatrelease2 key
  • OR
  • mariadb-server is earlier than 1:5.5.52-1.el7
  • AND mariadb-server is signed with Red Hat redhatrelease2 key
  • OR
  • mariadb-libs is earlier than 1:5.5.52-1.el7
  • AND mariadb-libs is signed with Red Hat redhatrelease2 key
  • OR
  • mariadb-test is earlier than 1:5.5.52-1.el7
  • AND mariadb-test is signed with Red Hat redhatrelease2 key
  • BACK