Oval Definition:oval:com.redhat.rhsa:def:20170184
Revision Date:2017-01-24Version:635
Title:RHSA-2017:0184: mysql security update (Important)
Description:MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries.

Security Fix(es):

  • It was discovered that the MySQL logging functionality allowed writing to MySQL configuration files. An administrative database user, or a database user with FILE privileges, could possibly use this flaw to run arbitrary commands with root privileges on the system running the database server. (CVE-2016-6662)

  • A race condition was found in the way MySQL performed MyISAM engine table repair. A database user with shell access to the server running mysqld could use this flaw to change permissions of arbitrary files writable by the mysql system user. (CVE-2016-6663, CVE-2016-5616)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-5616
    CVE-2016-6662
    CVE-2016-6663
    RHSA-2017:0184
    RHSA-2017:0184-00
    RHSA-2017:0184-01
    RHSA-2017:0184-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • mysql is earlier than 0:5.1.73-8.el6_8
  • AND mysql is signed with Red Hat redhatrelease2 key
  • mysql-bench is earlier than 0:5.1.73-8.el6_8
  • AND mysql-bench is signed with Red Hat redhatrelease2 key
  • mysql-devel is earlier than 0:5.1.73-8.el6_8
  • AND mysql-devel is signed with Red Hat redhatrelease2 key
  • mysql-embedded is earlier than 0:5.1.73-8.el6_8
  • AND mysql-embedded is signed with Red Hat redhatrelease2 key
  • mysql-embedded-devel is earlier than 0:5.1.73-8.el6_8
  • AND mysql-embedded-devel is signed with Red Hat redhatrelease2 key
  • mysql-libs is earlier than 0:5.1.73-8.el6_8
  • AND mysql-libs is signed with Red Hat redhatrelease2 key
  • mysql-server is earlier than 0:5.1.73-8.el6_8
  • AND mysql-server is signed with Red Hat redhatrelease2 key
  • mysql-test is earlier than 0:5.1.73-8.el6_8
  • AND mysql-test is signed with Red Hat redhatrelease2 key
  • BACK