Vulnerability Name: | CVE-2017-15945 (CCN-134204) | ||||||||||||
Assigned: | 2017-10-27 | ||||||||||||
Published: | 2017-10-27 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to the mysql account for creation of a link. | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-732 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-15945 Source: CCN Type: Gentoo's Bugzilla Bug 630822 (CVE-2017-15945) - dev-db/{mysql-cluster,mariadb,mysql,percona-server,mariadb-galera}: root privilege escalation via "chown" Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugs.gentoo.org/630822 Source: XF Type: UNKNOWN gentoo-cve201715945-priv-esc(134204) Source: GENTOO Type: Issue Tracking, Third Party Advisory GLSA-201711-04 Source: CCN Type: Gentoo Web site Welcome Gentoo Linux | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |