Vulnerability Name:

CVE-2017-15945 (CCN-134204)

Assigned:2017-10-27
Published:2017-10-27
Updated:2019-10-03
Summary:The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to the mysql account for creation of a link.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-732
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2017-15945

Source: CCN
Type: Gentoo's Bugzilla – Bug 630822
(CVE-2017-15945) - dev-db/{mysql-cluster,mariadb,mysql,percona-server,mariadb-galera}: root privilege escalation via "chown"

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory
https://bugs.gentoo.org/630822

Source: XF
Type: UNKNOWN
gentoo-cve201715945-priv-esc(134204)

Source: GENTOO
Type: Issue Tracking, Third Party Advisory
GLSA-201711-04

Source: CCN
Type: Gentoo Web site
Welcome – Gentoo Linux

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mariadb:mariadb:*:r1:*:*:*:*:*:* (Version < 10.0.30)
  • OR cpe:/a:mysql:mysql:*:r1:*:*:*:*:*:* (Version < 5.6.36)
  • AND
  • cpe:/o:gentoo:linux:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    mariadb mariadb * r1
    mysql mysql * r1
    gentoo linux -
    gentoo linux *